hardMultiple Choice
SSCP Practice Question: Based on the exhibit, what is the most…
Exhibit
Refer to the exhibit. [Vulnerability Scan Report Excerpt] Host: 10.0.0.15 Port: 3389 (RDP) Vulnerability: CVE-2024-1234 - Critical CVSS Score: 9.8 Description: Remote Code Execution in RDP Patch: KB4567890 available from vendor [Patch Management Database] Host 10.0.0.15: Last patched 2023-12-01. Patches applied: KB123456, KB789012. KB4567890 not applied. [Asset Criticality] 10.0.0.15: Critical, used for financial operations.
Based on the exhibit, what is the most appropriate immediate action?
⚠ Common exam trap
It's easy for candidates to choose to rescan or delay patching due to change management policies, failing to recognize that critical remote code execution vulnerabilities require immediate out-of-cycle patching to prevent imminent compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the vendor patch to the host as soon as possible
The exhibit shows a critical remote code execution vulnerability with a CVSS score of 9.8, which poses an immediate threat to the host. Applying the vendor patch as soon as possible is the most appropriate action because it directly eliminates the risk without delay, aligning with the principle of timely remediation for high-severity vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Schedule patching during the next change window in 30 days
Why it's wrong here
Deferring remediation for 30 days leaves an exploitable vulnerability unmitigated while the exhibit indicates active exposure requiring containment now. Change windows suit routine, low-risk updates; they are the right vehicle when no immediate threat exists and standard change control timelines apply.
- ✓
Apply the vendor patch to the host as soon as possible
Why this is correct
Patching directly addresses the exploited vulnerability on the affected host, satisfying the stem's demand for immediate containment. Unlike isolation or monitoring, which merely limit exposure, applying the vendor patch removes the underlying flaw, preventing further compromise. This makes it the most appropriate urgent action when the exhibit confirms an unpatched, actively targeted system.
- ✗
Run another vulnerability scan to confirm the finding
Why it's wrong here
Rescanning only re-confirms the finding and consumes time while the exposure persists; the exhibit already provides sufficient evidence to act. Verification scans are appropriate after remediation to confirm a fix, or when a finding's validity is genuinely uncertain, neither of which applies here.
- ✗
Ignore the vulnerability because it's a false positive
Why it's wrong here
Dismissing the finding as a false positive requires evidence the exhibit does not provide, and ignoring a validated vulnerability leaves the asset exposed. False-positive classification is correct only when scan data, version checks or vendor advisories confirm the reported condition does not actually exist on the target.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.