Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A vulnerability scan report shows that a web…

A vulnerability scan report shows that a web server has a critical vulnerability with a CVSS score of 9.8. However, the server is behind a WAF that blocks the attack vector, and the vulnerability is in a deprecated feature that cannot be removed until the next major release. What should the security manager do first?

⚠ Common exam trap

The trap here is that candidates mistakenly think a high CVSS score always demands immediate patching or removal, ignoring the role of compensating controls and formal risk acceptance in the risk management process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document the compensating control and accept the residual risk

The WAF serves as a compensating control that effectively mitigates the attack vector for this vulnerability, and the residual risk has been formally documented and accepted by management. In the absence of an immediate patch or removal of the deprecated feature, documenting the compensating control and accepting the residual risk is the appropriate risk management decision per the organization's risk appetite and the NIST SP 800-30 risk assessment framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remove the server from production

    Why it's wrong here

    Removing a critical web server from production is an extreme measure that would severely disrupt business operations and user access, potentially causing significant financial and reputational damage. While it eliminates the vulnerability, it's an overreaction when less disruptive risk treatment strategies, such as implementing compensating controls or applying patches, are available and more appropriate for managing risk without halting essential services. This action prioritizes security over availability to an unreasonable degree, failing to consider the business impact.

  • Ignore the finding because the WAF blocks it

    Why it's wrong here

    Simply ignoring a vulnerability because a Web Application Firewall (WAF) is in place is an irresponsible approach to risk management. While the WAF acts as a compensating control, mitigating the immediate threat, the underlying vulnerability still exists and could be exploited if the WAF is bypassed, misconfigured, or if the attack vector changes. Proper procedure requires formal risk acceptance, which involves documenting the residual risk, the compensating control, and obtaining management approval, rather than merely dismissing the finding without formal acknowledgment.

  • Document the compensating control and accept the residual risk

    Why this is correct

    This is the most appropriate action because it acknowledges the vulnerability while recognizing that an existing compensating control, such as a Web Application Firewall (WAF), effectively mitigates the immediate threat. Documenting the WAF as a compensating control provides an audit trail and demonstrates due diligence, showing that the organization has identified and addressed the risk. Formally accepting the residual risk, after confirming the control's effectiveness, ensures that management is aware of and approves the remaining risk level, balancing security with operational needs without immediate, disruptive action.

  • Immediately patch the vulnerability

    Why it's wrong here

    Immediately patching a vulnerability without proper assessment and testing can introduce new risks, potentially leading to system instability, application downtime, or compatibility issues with other software components. Patches may not always be readily available, or their application might require extensive regression testing to ensure they do not break critical business functionality. A hasty patch deployment, especially on a production system, often violates change management best practices and can cause more harm than good, outweighing the benefits of immediate remediation.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.