Courseiva

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security analyst is investigating a recent security incident where an attacker gained unauthorized access to a server. The analyst suspects the attacker used a known vulnerability in an outdated web application. Which of the following are the MOST appropriate steps to mitigate this vulnerability in the future? (Choose two.)

⚠ Common exam trap

The trap here is selecting compensating controls like WAF or segmentation as primary mitigations, when the question asks for steps to mitigate the vulnerability itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a patch management process to regularly update the web application.

The most effective ways to mitigate a known vulnerability in an outdated web application are to patch it regularly and to proactively identify vulnerabilities through scanning and remediation. These steps directly address the root cause by eliminating the vulnerable code. Other options like WAF, segmentation, or encryption are compensating controls or defense-in-depth measures, but they do not fix the underlying flaw.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a web application firewall (WAF) in blocking mode.

    Why it's wrong here

    A WAF can provide virtual patching and block exploit attempts, but it does not eliminate the underlying vulnerability. It is a compensating control, not a primary mitigation. The question asks for the MOST appropriate steps to mitigate the vulnerability itself, which requires patching or removing the vulnerable component, not just blocking attacks.

  • ✓

    Implement a patch management process to regularly update the web application.

    Why this is correct

    Regular patching ensures that known vulnerabilities are remediated promptly. In this scenario, the outdated web application likely had a publicly known exploit that could have been fixed by applying vendor patches. A formal patch management process includes inventory, testing, and deployment, reducing the window of exposure and preventing similar incidents.

  • ✗

    Implement network segmentation to isolate the web server.

    Why it's wrong here

    Network segmentation limits lateral movement and impact if a server is compromised, but it does not prevent the initial exploitation of a vulnerable web application. It is a defense-in-depth measure, not a direct mitigation of the vulnerability. The question focuses on mitigating the vulnerability itself, so segmentation alone is insufficient.

  • ✗

    Enable full disk encryption on the server.

    Why it's wrong here

    Full disk encryption protects data at rest if the server is physically stolen or improperly decommissioned. It does nothing to prevent remote exploitation of a web application vulnerability. Since the attack vector is network-based and targets application code, encryption at rest is irrelevant to mitigating this specific vulnerability.

  • ✓

    Perform a vulnerability scan and remediate findings on a regular schedule.

    Why this is correct

    Regular vulnerability scanning identifies outdated software and missing patches, enabling proactive remediation before attackers exploit them. In this incident, scanning would have flagged the outdated web application and prompted action. Combining scanning with remediation ensures that vulnerabilities are not just identified but also fixed, directly addressing the root cause.

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.