easyMultiple Choice
PT0-002 Practice Question: Is an example of a responsible remediation…
Which of the following is an example of a responsible remediation recommendation?
⚠ Common exam trap
CompTIA Pentest+ often tests the distinction between a specific, actionable remediation (with version numbers) and a generic security policy statement, trapping candidates who choose broad advice like 'apply patches regularly' instead of a precise fix.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Upgrade Apache to version 2.4.51 to fix the vulnerability.
It provides a specific, actionable remediation: upgrading Apache to version 2.4.51, which is known to address a particular vulnerability (e.g., CVE-2021-41773 or CVE-2021-42013 for path traversal). A responsible recommendation must include a concrete version number or patch identifier to ensure the fix is verifiable and not ambiguous.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Upgrade Apache to version 2.4.51 to fix the vulnerability.
Why this is correct
Recommending a specific vendor version upgrade gives the client an actionable, verifiable fix for the identified Apache flaw. It names the exact target release, so the technical team can patch and confirm remediation rather than receive a vague instruction to harden the service.
- ✗
Apply security patches regularly.
Why it's wrong here
Too general; doesn't address the specific finding.
- ✗
Update the web server software.
Why it's wrong here
Updating web server software is a general maintenance action that does not map to the particular vulnerability reported, leaving the actual exposure unaddressed. It is tempting because version currency does close known CVEs, and it would be the right recommendation when the finding specifically identifies an outdated web server component.
- ✗
Configure the firewall to block all incoming traffic.
Why it's wrong here
Blocking all inbound traffic would halt legitimate business services alongside the vulnerability, exceeding the scope of the finding and breaking availability. It is tempting as an apparently safe hardening step, yet it is the correct choice only when a host is confirmed compromised and must be isolated immediately.
Go deeper
Related to this question
Learn chapter
Remediation Recommendations
Key term
Remediation recommendation
A remediation recommendation is a prioritized, actionable suggestion for fixing a security vulnerability, misconfiguration, or compliance gap identified during an assessment or scan.
Key term
CVE
CVE stands for Common Vulnerabilities and Exposures, which is a publicly available list of standardized identifiers for known security vulnerabilities in software and hardware.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.