mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is recommending remediation…
A penetration tester is recommending remediation for a critical vulnerability. Which of the following is the best example of a specific, actionable remediation step?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Upgrade Apache from version 2.4.49 to 2.4.51.
Effective remediation should be specific, including exact versions or commands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply security patches.
Why it's wrong here
This remediation is too vague to be actionable. It does not identify the specific CVE (e.g., CVE-2021-41773) or the affected Apache version (2.4.49), nor does it name the patched release (2.4.51) that resolves the issue. A client cannot verify whether the patch was applied correctly without these details, and the statement is likely to be ignored in a change-management workflow.
- ✓
Upgrade Apache from version 2.4.49 to 2.4.51.
Why this is correct
This is the correct, specific remediation because it precisely names the vulnerable software (Apache HTTP Server), the affected version (2.4.49), and the exact fixed version (2.4.51). Upgrading from 2.4.49 to 2.4.51 directly addresses path traversal and remote code execution vulnerabilities tracked as CVE-2021-41773 and CVE-2021-42013. This concrete instruction is testable, verifiable, and provides clear guidance for the client's system administration team.
- ✗
Update the software to the latest version.
Why it's wrong here
While updating to the latest version is a good general practice, it is not a precise remediation recommendation. "Latest" is a moving target and does not guarantee that the upgrade specifically addresses the identified vulnerability—a newer version could introduce unrelated features or breaking changes. The recommendation should specify the exact patched release (2.4.51) that has been tested and confirmed to fix the vulnerability, rather than leaving the target version ambiguous.
- ✗
Fix the vulnerability.
Why it's wrong here
This statement merely restates the desired outcome without providing any technical instruction. To remediate a vulnerability, the client needs to know which component is affected, the exact vulnerable version, and the specific action to take (such as upgrading Apache to 2.4.51 or modifying a configuration). "Fix the vulnerability" contains no actionable detail and cannot be implemented or verified by the client's team.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.