Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A vulnerability scan reports a critical finding on a legacy application server. The security team verifies that the flagged package is installed, but the vulnerable code path is disabled by configuration and cannot be exploited in the current deployment. The vendor will not support a patch until next quarter. What is the best next step?

⚠ Common exam trap

Candidates often confuse a 'false positive' (scanner error) with a 'vulnerability that is mitigated by a compensating control' — the scanner is correct, but the risk is lower than the raw CVSS score suggests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Request a risk exception and document compensating controls until patching is possible

The vulnerability is real (the package is installed), but the risk is mitigated by a compensating control (the vulnerable code path is disabled). A risk exception formally documents this compensating control and the planned patch timeline, ensuring the finding is tracked and not forgotten. This aligns with the SY0-701 objective of managing risk through formal acceptance and compensating controls when immediate remediation is not possible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ignore the finding because the scanner produced a false positive

    Why it's wrong here

    Labeling the finding as a false positive without manual verification is an unsubstantiated dismissal that bypasses the organization's vulnerability management process. Even if exploitation is currently blocked by existing network controls, the finding should be formally assessed, documented, and either remediated or accepted with a risk exception. Ignoring it leaves no audit trail and fails to demonstrate due diligence, which could be problematic for compliance requirements.

  • Request a risk exception and document compensating controls until patching is possible

    Why this is correct

    This is the best response because the team has confirmed the issue cannot be immediately remediated, but the organization still needs formal risk ownership. A risk exception documents the temporary acceptance, while compensating controls capture what is being done to reduce exposure until a supported patch becomes available. That is the right balance between operational constraints and security governance.

  • Disable the vulnerability scanner to prevent repeated alerts

    Why it's wrong here

    Disabling the vulnerability scanner is a reactive measure that removes the detective control responsible for continuous monitoring, leaving the organization blind to the actual exposure. This action does not reduce or eliminate the underlying vulnerability; it simply suppresses the alert, preventing the security team from verifying whether mitigating controls are effective or whether the vulnerability is later exploited. It also breaks audit and compliance evidence trails, as scanning continuity is often mandated by frameworks like PCI DSS or NIST.

  • Immediately retire the server even though the application is still business-critical

    Why it's wrong here

    Immediately retiring a business-critical server is a disproportionate response when the application remains necessary for operations, as it could cause significant downtime, revenue loss, or adverse mission impact. The security team should instead evaluate the urgency of the vulnerability and implement compensating controls—such as network segmentation, strict access controls, or host-based firewalls—while requesting a formal risk exception with a planned patch date. This balances security risk with business continuity, allowing the system to remain functional while actively reducing its exploitability.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.