Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator is prioritizing patches for a vulnerability with a CVSS score of 9.8 that is being actively exploited in the wild. The affected server has a low criticality classification. What should the administrator do?

⚠ Common exam trap

SSCP often tests the misconception that low asset criticality justifies ignoring critical vulnerabilities—candidates may pick 'ignore' or 'wait' without considering active exploitation and lateral movement risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prioritize patching via the change management process

Even though the server is low criticality, a CVSS score of 9.8 with active exploitation represents an urgent risk that must be addressed. The administrator should prioritize patching through the change management process to ensure proper approval, testing, and documentation while still expediting the fix.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the patch immediately without change management

    Why it's wrong here

    Applying the patch immediately bypasses change management, which still applies to emergency patches; an emergency change process exists for exactly this situation. Skipping it tempts because active exploitation demands speed, yet unrecorded changes risk outages and audit failures, so the patch should follow the emergency change procedure.

  • ✗

    Ignore the patch because the server is low criticality

    Why it's wrong here

    Active exploitation plus a CVSS score of 9.8 outweighs the server's low criticality classification, so the patch must be applied. Ignoring it tempts because criticality ratings normally guide prioritisation, but exploited vulnerabilities demand emergency remediation regardless of the asset's business classification.

  • ✗

    Wait for the next scheduled patch cycle

    Why it's wrong here

    Active exploitation with CVSS 9.8 demands emergency remediation regardless of server criticality, since compromise can pivot to higher-value assets. Waiting for the scheduled cycle leaves the vulnerability exploitable for weeks. Scheduled cycles suit low-severity issues with no known exploitation and no compensating controls in place.

  • ✓

    Prioritize patching via the change management process

    Why this is correct

    Active exploitation plus a CVSS of 9.8 outweighs the server's low criticality, so the patch must be expedited. Routing it through change management satisfies the stem by ensuring the urgent fix is deployed under controlled, documented approval rather than bypassing governance entirely.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.