Courseiva
Security Operations →mediumMultiple Choice

ISC2 CC Security Operations Practice Question

A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?

⚠ Common exam trap

CC often tests whether candidates default to 'always test before deploying' — but when a zero-day is actively exploited, the correct answer is the emergency patch without full testing, because the standard lifecycle's delay is itself the greater risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy an emergency patch without testing.

When a zero-day vulnerability is actively exploited in the wild against an internet-facing application, the risk of waiting for full testing outweighs the risk of deploying an untested emergency patch. An emergency patch (or vendor hotfix) is deployed immediately with expedited change approval, because the active exploitation represents an imminent, ongoing threat that standard change-management timelines cannot accommodate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Isolate the application from the network and wait for a vendor patch.

    Why it's wrong here

    Isolating the application halts the business service entirely, which is disproportionate when a mitigation can block the exploit while a vendor patch is developed. It is tempting as a containment reflex, and would be right if the application were non-critical or the exploit unmitigable, but here it sacrifices availability unnecessarily.

  • ✓

    Deploy an emergency patch without testing.

    Why this is correct

    Deploying an emergency patch without testing is the appropriate response due to the immediate and severe threat posed by a critical zero-day vulnerability actively being exploited in the wild. The paramount concern is to halt active exploitation and prevent further compromise as quickly as possible. While rigorous testing is normally crucial, the urgency of stopping an ongoing attack outweighs the risks associated with an untested deployment, directly addressing the constraint of mitigating an active, critical threat.

  • ✗

    Implement a web application firewall (WAF) as a permanent solution.

    Why it's wrong here

    A WAF filters HTTP traffic but cannot remediate the vulnerable code itself, so the underlying flaw persists and may be reached via non-HTTP vectors. It is tempting as an immediate virtual patch, and is valid as a compensating control, but it cannot serve as the permanent fix the question demands.

  • ✗

    Follow the standard patch lifecycle with testing.

    Why it's wrong here

    Standard lifecycle testing takes days or weeks, leaving the internet-facing application exploitable throughout active attacks. It is tempting because it is the default governance path, and it would be correct for routine patches, but an emergency change with expedited testing is required when exploitation is confirmed in the wild.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.