SY0-701 Security Operations Practice Question
A vulnerability scan finds a critical flaw on a public-facing server and a medium flaw on a lab system that is not connected to the production network. Which issue should be fixed first?
⚠ Common exam trap
A common mix-up: candidates assume all vulnerabilities must be fixed in order of severity alone, ignoring the crucial factor of asset exposure and business context, or they may mistakenly believe that internal systems are always more critical than external ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The critical flaw on the public-facing server, because it has higher business risk.
The critical flaw on the public-facing server should be fixed first because it presents a higher business risk. A public-facing server is directly accessible from the internet, making it a prime target for attackers. Exploiting a critical vulnerability could lead to data breaches, service disruption, or unauthorized access, with immediate and severe business impact. In contrast, the medium flaw on an isolated lab system poses no direct threat to production operations or sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The medium flaw on the isolated lab system, because all vulnerabilities should be fixed in alphabetical order.
Why it's wrong here
Selecting vulnerabilities for remediation alphabetically ignores the core tenet of risk management: prioritize by likelihood of exploitation and magnitude of business impact. A medium-severity flaw on an isolated lab system typically has minimal attack surface and low value at risk, whereas a critical flaw exposed to the internet can be chained into system compromise or data exfiltration. Remediation order should be driven by business risk, not lexicographic order.
- ✓
The critical flaw on the public-facing server, because it has higher business risk.
Why this is correct
The critical flaw on the public-facing server is the clear first priority because the combination of high severity and direct internet exposure dramatically increases both the probability of exploitation and the potential business impact. Critical vulnerabilities often have publicly available proof-of-concept exploits or are leveraged in automated attacks, so the remediation window is short. Addressing this server first reduces the likelihood of a successful attack that could affect customers, brand reputation, or regulatory compliance.
- ✗
Both systems can wait until the next quarterly patch cycle.
Why it's wrong here
Deferring a critical public-facing vulnerability to the next quarterly patch cycle leaves a known exploit avenue open for an extended period, which is contrary to security best practice for high-risk findings. Many critical vulnerabilities are exploited within days or hours of disclosure, making a static quarterly window dangerously slow. Organizations should implement an emergency change advisory or out-of-band patching process for critical internet-facing assets to close the vulnerability before it is weaponized.
- ✗
The lab system, because internal systems always outrank external systems.
Why it's wrong here
The assumption that internal systems always outrank external systems is flawed because risk is a function of exposure, asset value, and existing compensating controls. An internal lab system might be isolated and accessible only to a small set of authenticated users, whereas an external server faces constant scanning and attack attempts. Moreover, the lab system may not hold sensitive data, so the business impact of a compromise could be negligible. Risk prioritization must consider the actual threat landscape and the criticality of the asset to the organization's mission.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.