SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst is investigating a recent security incident where an attacker gained unauthorized access to a server. The analyst suspects the attacker used a known vulnerability in an outdated web application. Which of the following are the MOST appropriate steps to mitigate this vulnerability in the future? (Choose two.)
⚠ Common exam trap
The trap here is selecting compensating controls like WAF or segmentation as primary mitigations, when the question asks for steps to mitigate the vulnerability itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a patch management process to regularly update the web application.
The most effective ways to mitigate a known vulnerability in an outdated web application are to patch it regularly and to proactively identify vulnerabilities through scanning and remediation. These steps directly address the root cause by eliminating the vulnerable code. Other options like WAF, segmentation, or encryption are compensating controls or defense-in-depth measures, but they do not fix the underlying flaw.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a web application firewall (WAF) in blocking mode.
Why it's wrong here
A WAF can provide virtual patching and block exploit attempts, but it does not eliminate the underlying vulnerability. It is a compensating control, not a primary mitigation. The question asks for the MOST appropriate steps to mitigate the vulnerability itself, which requires patching or removing the vulnerable component, not just blocking attacks.
- ✓
Implement a patch management process to regularly update the web application.
Why this is correct
Regular patching ensures that known vulnerabilities are remediated promptly. In this scenario, the outdated web application likely had a publicly known exploit that could have been fixed by applying vendor patches. A formal patch management process includes inventory, testing, and deployment, reducing the window of exposure and preventing similar incidents.
- ✗
Implement network segmentation to isolate the web server.
Why it's wrong here
Network segmentation limits lateral movement and impact if a server is compromised, but it does not prevent the initial exploitation of a vulnerable web application. It is a defense-in-depth measure, not a direct mitigation of the vulnerability. The question focuses on mitigating the vulnerability itself, so segmentation alone is insufficient.
- ✗
Enable full disk encryption on the server.
Why it's wrong here
Full disk encryption protects data at rest if the server is physically stolen or improperly decommissioned. It does nothing to prevent remote exploitation of a web application vulnerability. Since the attack vector is network-based and targets application code, encryption at rest is irrelevant to mitigating this specific vulnerability.
- ✓
Perform a vulnerability scan and remediate findings on a regular schedule.
Why this is correct
Regular vulnerability scanning identifies outdated software and missing patches, enabling proactive remediation before attackers exploit them. In this incident, scanning would have flagged the outdated web application and prompted action. Combining scanning with remediation ensures that vulnerabilities are not just identified but also fixed, directly addressing the root cause.
Go deeper
Related to this question
Learn chapter
Race Condition Vulnerabilities
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
WAF
A Web Application Firewall (WAF) is a security tool that filters, monitors, and blocks HTTP traffic to and from a web application to protect it from common attacks.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.