Courseiva
Question 386 of 1,013
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A scan keeps reporting the same medium-severity TLS configuration issue on a public web server. The application owner says the vendor software cannot be changed until next quarter, but they can place the service behind a reverse proxy that enforces stronger cipher settings. How should the issue be handled in the vulnerability management process?

⚠ Common exam trap

Many candidates assume a compensating control automatically closes the finding, when in fact vulnerability management requires an exception process with documentation and a future remediation date to ensure the root cause is eventually addressed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Record an exception, document the compensating control, and set a review or remediation date

The vulnerability management process requires that when a vulnerability cannot be immediately remediated, compensating controls must be formally documented as an exception with a scheduled remediation date. In this scenario, the reverse proxy enforces stronger cipher settings, effectively mitigating the TLS misconfiguration at the network edge, which is a valid compensating control. Recording the exception ensures auditability and prevents the finding from being prematurely closed while the vendor software remains vulnerable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Close the finding as fixed because the reverse proxy reduces the risk

    Why it's wrong here

    Marking the finding as fixed is incorrect because the scanner is reporting a real TLS configuration weakness in the origin server itself, not in the reverse proxy. A compensating control that terminates TLS at the proxy does not remediate the vulnerable component; the backend may still be directly accessible or misconfigured for internal communications. Closing the finding as fixed without documenting the proxy as an exception removes visibility and accountability, and any future change to the proxy could instantly expose the underlying issue.

  • Record an exception, document the compensating control, and set a review or remediation date

    Why this is correct

    Recording an exception is the correct approach because the vulnerability is genuine but the organization is choosing to accept the residual risk in exchange for a documented compensating control (the reverse proxy). This formal risk acceptance process ensures that the finding remains visible, involves the appropriate decision-makers, and assigns a review or remediation date so the risk is revisited rather than forgotten. It also provides an audit trail that clearly distinguishes between a false positive and a deliberate, managed risk acceptance, which is essential for compliance frameworks like PCI DSS or NIST.

  • Mark the finding as a false positive and remove it from future scans

    Why it's wrong here

    Marking this as a false positive is wrong because the scanner is accurately detecting a real TLS misconfiguration on the host, even though a reverse proxy mitigates exposure to external clients. A false positive means the reported issue does not exist, but here the issue is present and only compensated for at another layer. Removing the finding from future scans could hide the risk entirely, and if the compensating control changes or is misconfigured, the organization would have no automated alert or documented record to prompt corrective action.

  • Ignore the finding until the vendor releases a new version

    Why it's wrong here

    Ignoring the finding while waiting for a vendor patch is not acceptable because it fails to document a named risk owner, a mitigation strategy, or a follow-up timeline. In many cases a patch may never be released, or the vulnerability could be mitigated sooner through configuration changes or virtual patching, but ignoring the report precludes those options. A formal exception with a review date is the appropriate way to defer remediation, as it maintains accountability and ensures the risk is monitored until a permanent fix is available.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.