Courseiva
hardMultiple Choice

SSCP Practice Question: Based on the exhibit, what is the most…

Exhibit

Refer to the exhibit.

[Vulnerability Scan Report Excerpt]
Host: 10.0.0.15
Port: 3389 (RDP)
Vulnerability: CVE-2024-1234 - Critical
CVSS Score: 9.8
Description: Remote Code Execution in RDP
Patch: KB4567890 available from vendor

[Patch Management Database]
Host 10.0.0.15: Last patched 2023-12-01. Patches applied: KB123456, KB789012.
KB4567890 not applied.

[Asset Criticality]
10.0.0.15: Critical, used for financial operations.

Based on the exhibit, what is the most appropriate immediate action?

⚠ Common exam trap

It's easy for candidates to choose to rescan or delay patching due to change management policies, failing to recognize that critical remote code execution vulnerabilities require immediate out-of-cycle patching to prevent imminent compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the vendor patch to the host as soon as possible

The exhibit shows a critical remote code execution vulnerability with a CVSS score of 9.8, which poses an immediate threat to the host. Applying the vendor patch as soon as possible is the most appropriate action because it directly eliminates the risk without delay, aligning with the principle of timely remediation for high-severity vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Schedule patching during the next change window in 30 days

    Why it's wrong here

    Deferring remediation for 30 days leaves an exploitable vulnerability unmitigated while the exhibit indicates active exposure requiring containment now. Change windows suit routine, low-risk updates; they are the right vehicle when no immediate threat exists and standard change control timelines apply.

  • ✓

    Apply the vendor patch to the host as soon as possible

    Why this is correct

    Patching directly addresses the exploited vulnerability on the affected host, satisfying the stem's demand for immediate containment. Unlike isolation or monitoring, which merely limit exposure, applying the vendor patch removes the underlying flaw, preventing further compromise. This makes it the most appropriate urgent action when the exhibit confirms an unpatched, actively targeted system.

  • ✗

    Run another vulnerability scan to confirm the finding

    Why it's wrong here

    Rescanning only re-confirms the finding and consumes time while the exposure persists; the exhibit already provides sufficient evidence to act. Verification scans are appropriate after remediation to confirm a fix, or when a finding's validity is genuinely uncertain, neither of which applies here.

  • ✗

    Ignore the vulnerability because it's a false positive

    Why it's wrong here

    Dismissing the finding as a false positive requires evidence the exhibit does not provide, and ignoring a validated vulnerability leaves the asset exposed. False-positive classification is correct only when scan data, version checks or vendor advisories confirm the reported condition does not actually exist on the target.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.