SY0-701 Security Operations Practice Question
Exhibit
Weekly vulnerability report: 1. vpn-gw01 - Exposure: Internet-facing - Finding: Critical remote code execution - Notes: Vendor patch available; reboot required 2. db-lab02 - Exposure: Internal only - Finding: High-severity authentication bypass - Notes: Isolated lab subnet; no sensitive data; no route to production 3. printsrv03 - Exposure: Internet-facing administrative portal - Finding: Medium-severity outdated firmware - Notes: Vendor has not released a fix yet; temporary ACL blocks the admin port from the internet
Based on the exhibit, which issue should be remediated first by the operations team?
A small company has limited maintenance windows and can address only one of several findings this week.
⚠ Common exam trap
Many exam-takers assume severity (e.g., critical vs. high) is the sole determinant of remediation priority, ignoring the critical factors of internet exposure, exploitability, and patch availability that CompTIA emphasizes in risk management scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vpn-gw01, because it is internet-facing, exploitable now, and a fix is available.
Vpn-gw01 is internet-facing, has an active exploit (CVSS score indicating current exploitation), and a vendor patch is available. In risk management, the highest priority is given to assets that are exposed to the internet, currently exploitable, and have a known fix, as this combination presents the most urgent threat to the organization's security posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
db-lab02, because high-severity findings always outrank medium and critical findings.
Why it's wrong here
The premise is factually flawed: severity cannot be treated as the sole priority factor, and ‘high’ does not outrank ‘critical’ in any standard risk matrix. db-lab02 is a lab database isolated from production, so even if it contains a high-severity vulnerability, the likelihood of exploitation and business impact are low. A proper vulnerability management program scores by exploitability, exposure, asset criticality, and compensating controls — none of which favor db-lab02 over vpn-gw01.
- ✗
printsrv03, because it is internet-facing and has no vendor patch available.
Why it's wrong here
The absence of a vendor patch actually makes printsrv03 a poor candidate for immediate remediation — you cannot deploy a fix that does not exist. The temporary ACL already mitigates the exposure, reducing the immediate likelihood of compromise. Prioritization favors vpn-gw01 because a vendor-provided patch is available and can be applied now, turning a critical internet-facing vulnerability into a closed risk. Deferring a fixable critical vulnerability while waiting for a vendor patch elsewhere is backwards.
- ✓
vpn-gw01, because it is internet-facing, exploitable now, and a fix is available.
Why this is correct
The VPN gateway is the most urgent issue because it is externally reachable, has a critical remote code execution flaw, and a vendor patch already exists. That combination creates high likelihood and high impact. The reboot requirement is inconvenient, but it is still the most actionable and dangerous finding. The other issues are either isolated from production or partially mitigated by compensating controls.
- ✗
None of these, because the team should wait for the next quarterly review before changing anything.
Why it's wrong here
Deferring all remediation to a quarterly review ignores basic incident-response and vulnerability-management principles: any critical, externally exploitable flaw with an available patch demands urgent action, not administrative delay. The reboot required by vpn-gw01's patch is a minor availability trade-off compared to the risk of remote code execution. A quarterly review is useful for planning long-term improvements, but it cannot supersede the need to close an active attack vector. In practice, waiting would leave a known, exploitable path open for months.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.