Courseiva
Security Operations and AdministrationhardMultiple ChoiceObjective-mapped

SSCP Security Operations and Administration Practice Question

A vulnerability scan identifies a critical vulnerability on a web server with a CVSS score of 9.8. The server hosts a public-facing application. However, the patch would require a reboot that would cause downtime during business hours. What should the security administrator do FIRST?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assess the risk and implement compensating controls if possible

The first step is to assess the risk and prioritise based on exploitability and asset criticality. A CVSS 9.8 vulnerability is critical, so immediate action is needed, but the administrator should evaluate compensating controls before applying the patch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assess the risk and implement compensating controls if possible

    Why this is correct

    Perform risk assessment to determine if the vulnerability can be mitigated via other controls (e.g., WAF) or if downtime is necessary.

  • Schedule the patch for the next maintenance window without further analysis

    Why it's wrong here

    Scheduling without analysis may leave the system exposed for too long.

  • Apply the patch immediately during business hours

    Why it's wrong here

    Applying immediately may cause unnecessary downtime without assessing impact.

  • Document the exception and ignore the vulnerability

    Why it's wrong here

    Ignoring a critical vulnerability without justification is not acceptable.

About these practice questions

Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.