SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A vulnerability scan of a branch-office print server finds that its administrative web console is reachable from the internet. The appliance is still using the vendor's default password, and no access control list limits management access to the office subnet or VPN. Which remediation would reduce risk the most with the least disruption?
⚠ Common exam trap
Many candidates choose Option B (disable and replace) because it seems most secure, but they overlook that configuration changes (ACL and password reset) achieve the same security goal with far less disruption and cost.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict management access to the office network or VPN and change the default credentials.
Reduces risk the most with the least disruption by immediately addressing the two primary vulnerabilities: the default password and unrestricted internet exposure. Changing the default credentials prevents trivial authentication bypass, while restricting management access to the office subnet or VPN eliminates the attack surface from the public internet. This approach requires no hardware replacement or downtime, and it directly mitigates the highest-severity issues identified in the scan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the password length policy and leave the console publicly reachable.
Why it's wrong here
Lengthening passwords only affects future password choices; it does nothing to reduce the current exposure of the management console to the internet. The console remains reachable by anyone, allowing brute-force attempts, credential-stuffing, or exploitation of any vulnerability in the web interface itself. Even with a strong password, the device's administrative functions are still publicly accessible, which is an unnecessary and direct attack surface. Access control (e.g., IP whitelisting) is a more immediate and effective mitigation than a policy change.
- ✗
Disable the management interface entirely and replace the device immediately.
Why it's wrong here
Immediately disabling the management interface and replacing the device is a heavy-handed, costly response that ignores the actual scope of the finding. The management interface is often required for routine administration, monitoring, and configuration changes; removing it entirely could cripple operations even if a less disruptive control would suffice. Replacement also introduces deployment time and procurement cost, and the same vulnerability could remain if the replacement is not properly configured. The scan indicates a misconfiguration (public exposure with default credentials), not necessarily a hardware defect that mandates replacement.
- ✓
Restrict management access to the office network or VPN and change the default credentials.
Why this is correct
This is the best balance of security and operational impact. Publicly exposed administration interfaces are high-risk, especially when default credentials are still enabled. Limiting access to a trusted management network or VPN immediately reduces attack surface, while changing the vendor defaults removes a common compromise path. Together, these steps address the exposure without requiring a full replacement or major service outage.
- ✗
Apply a patch after the next quarterly maintenance window and keep the current exposure unchanged.
Why it's wrong here
Delaying remediation until the next quarterly maintenance window leaves the print server exposed to the internet with both a public management interface and known default credentials. A patch, if one exists, may address a specific software vulnerability but does not fix the configuration issue of open administration access or change the vendor-supplied credentials. During the waiting period, the device is a high-priority target because the default credentials are publicly documented, making unauthorized access trivial. Immediate actions—such as restricting network access and rotating credentials—are safer than waiting for a scheduled patch cycle.
Visual reference
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning and Assessment
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.