Courseiva
Question 953 of 1,013
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A weekly scan reports three findings: a medium-severity missing patch on a lab VM with no network access, a high-severity default credential on a management interface reachable from the internet, and a low-severity outdated browser plug-in on a visitor kiosk. Which issue should be remediated first?

⚠ Common exam trap

The trap here is that candidates focus solely on the severity label (high vs. medium vs. low) without considering the compensating controls or exposure, leading them to incorrectly rank the missing patch or outdated plug-in as higher priority.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The high-severity default credential on the management interface exposed to the internet.

The high-severity default credential on a management interface reachable from the internet represents an immediate, exploitable risk. Default credentials are well-known and can be used by attackers to gain full administrative control over the device, often leading to a complete compromise of the network. In contrast, the other findings have compensating controls (no network access) or lower impact (outdated browser plug-in), making them lower priority in a risk-based remediation strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The medium-severity missing patch on the isolated lab VM.

    Why it's wrong here

    The isolated lab VM has no network access, so although a missing patch is a weakness, the attack surface is limited to physical or local attackers. The medium severity indicates moderate impact, but because the system is not reachable from the network, the likelihood of exploitation is dramatically reduced. Thus, it should not outrank an internet-exposed system with high-severity issues.

  • The low-severity outdated browser plug-in on the visitor kiosk.

    Why it's wrong here

    The visitor kiosk is likely a non-administrative, restricted-purpose system, and an outdated browser plug-in is rated low severity, meaning the potential impact is limited. Even if the plug-in has known vulnerabilities, exploitation typically requires user interaction and the kiosk may have software restriction policies. This finding, while worthy of attention, carries far less risk than a default credential on an internet-facing management interface.

  • The high-severity default credential on the management interface exposed to the internet.

    Why this is correct

    Default credentials on a management interface exposed to the internet represent a critical risk because they are publicly known, easily tested by automated tools, and provide immediate administrative access if successfully used. The internet exposure makes the vulnerability remotely exploitable without authentication, and a management interface often has elevated privileges, enabling full system control. This combination of high severity, high exploitability, and direct internet accessibility must be the top priority.

  • All three issues have the same priority because they were found in the same scan cycle.

    Why it's wrong here

    Prioritizing findings solely because they were found in the same scan cycle ignores the fundamental principles of risk assessment, where likelihood and impact outweigh scan timing. Severity, asset criticality, network exposure, and the presence of compensating controls all vary among the three findings, so they inherently have different urgency. Treating all findings equally could lead to fixing a low-risk issue while a critical internet-facing flaw remains exploitable.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.