mediumMultiple Select
PT0-002 Practice Question: A penetration tester discovers a vulnerability…
A penetration tester discovers a vulnerability that cannot be immediately remediated. Which TWO compensating controls should the tester recommend? (Choose TWO.)
⚠ Common exam trap
Candidates often confuse compensating controls with remediation actions, selecting 'upgrade the software immediately' (E) even though the scenario explicitly states the vulnerability cannot be immediately remediated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement network segmentation to limit exposure.
Option C is correct because network segmentation (e.g., placing the vulnerable host in a restricted VLAN or behind firewall ACLs) is a classic compensating control that reduces the attack surface and limits lateral movement even when the underlying flaw cannot be patched right away. Option D is correct because an IDS provides detective compensating control value: it monitors network traffic or host activity for signatures/anomalies indicating exploitation attempts, enabling rapid response while remediation is deferred. Option A is not a compensating control but a disruptive remediation action that removes functionality rather than mitigating risk while preserving the service. Option B is simply risk acceptance/neglect, not a control, and leaves the vulnerability unmonitored. Option E is immediate remediation, which the scenario explicitly rules out as not possible right now.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the affected service entirely.
Why it's wrong here
Disabling the service is a direct remediation action, not a compensating control, because it removes the vulnerability by completely eliminating the attack surface. However, this also ceases the business function the service provides, which is equivalent to causing a denial of service to legitimate users. In most penetration test scenarios, the service is critical to operations, so merely turning it off is a valid final fix but is not an interim risk-reduction measure.
- ✗
Ignore the vulnerability until the next patch cycle.
Why it's wrong here
Ignoring a confirmed vulnerability is a failure to implement any form of risk reduction; it does not meet the definition of a compensating control, which explicitly requires an alternate security measure to replace the missing fix. While waiting for a vendor patch is normal, the organization must actively apply compensating measures such as hardening the service, restricting access, or deploying monitoring. Simply accepting the exposure without formal risk acceptance is a due-care violation and could be considered negligent.
- ✓
Implement network segmentation to limit exposure.
Why this is correct
Network segmentation is a textbook compensating control: it does not patch the vulnerable software, but it reduces the attack surface by isolating the affected system from untrusted hosts. Techniques such as placing the server in a separate VLAN, enforcing strict firewall ingress/egress rules, or applying zero-trust micro-segmentation restrict the paths an attacker can use to reach the vulnerability. This is a pragmatic, immediately actionable measure that can be implemented while awaiting a permanent fix, and it also minimizes the blast radius if the service is compromised.
- ✓
Add an intrusion detection system (IDS) to monitor for exploitation.
Why this is correct
An IDS implemented alongside a known, unpatched vulnerability provides a compensating control by generating alerts when an attacker attempts to exploit it. Because it has no effect on the exploit's success, it must be paired with a robust incident response capability to ensure alerts are actually acted upon. The main value is reducing the dwell time: instead of relying on chance to detect a breach, the organization gains earliest possible notification and can contain the intrusion before data loss or lateral movement occurs.
- ✗
Upgrade the software immediately.
Why it's wrong here
Upgrading the affected software is the definitive remediation because it addresses the root cause of the vulnerability and eliminates the flaw entirely. Unlike compensating controls, which merely mitigate risk through alternate safeguards, an upgrade provides a permanent fix, so it cannot be classified as a compensatory measure. When an upgrade is already available and can be applied immediately, it should always be the primary recommendation, not a temporary workaround.
Visual reference
Go deeper
Related to this question
Learn chapter
RDP Exploitation and BlueKeep
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.