SY0-701 exam dumps

SY0-701 practice question 183 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 183

Single answerPatch availability

A security administrator is reviewing vulnerability scan results for a public-facing application server that hosts a critical customer portal. The scan shows a newly disclosed remote code execution vulnerability affecting the server's web service. The software vendor has acknowledged the issue, but no security patch is available yet. Management is concerned about uptime and does not want to take the portal offline unless absolutely necessary. Which of the following is the BEST action for the administrator to take first?

  1. A

    Implement compensating controls such as a web application firewall rule or IPS signature, restrict exposure where possible, and closely monitor the system until a vendor patch is released

  2. B

    Wait for the vendor to release an official patch because temporary controls can create instability and are not a valid security response

  3. C

    Uninstall the vulnerable web service immediately, even if that makes the customer portal unavailable, because patch availability is the only factor that matters

  4. D

    Mark the vulnerability as a false positive since the vendor has not yet published a patch and rescan after the next maintenance window

Show answer and explanation

Correct answer: A

Explanation

This question focuses on patch availability within vulnerability and risk management. In security operations, a known vulnerability does not become acceptable simply because a vendor patch is not yet released. Best practice is to evaluate exploitability, exposure, asset criticality, and business impact, then apply compensating controls while tracking the issue through change and patch management processes. Common sources of guidance include vendor security advisories, CISA alerts and Known Exploited Vulnerabilities guidance, and NIST vulnerability management principles such as risk-based mitigation and temporary safeguards when full remediation is unavailable. For Security+, candidates should recognize that patch availability affects remediation strategy, but it does not eliminate the need to reduce risk immediately.

  • A. Correct.

    Correct. When a vulnerability is confirmed but no patch is yet available, the best initial response is to apply compensating controls to reduce risk while maintaining availability. In a real environment, this can include WAF rules, IPS/IDS signatures, ACL changes, segmentation, disabling affected features, limiting internet exposure, and heightened logging/monitoring. This aligns with common vulnerability management and risk treatment practices: if remediation is not immediately possible, organizations should mitigate exposure until a permanent fix is available.

  • B. Incorrect.

    Incorrect. Waiting passively for a patch leaves the organization exposed to a known vulnerability, especially for an internet-facing critical system. Temporary or compensating controls are a standard and necessary response when patches are unavailable. The misconception here is that only vendor patches count as remediation; in practice, mitigation steps are often required first.

  • C. Incorrect.

    Incorrect. Taking the service offline may reduce risk, but the question states management wants to preserve uptime unless absolutely necessary. Immediate removal of the service is not the best first step if other reasonable mitigations can reduce risk while maintaining business operations. Service shutdown may become necessary later if compensating controls are insufficient, but it is not the best initial action in this scenario.

  • D. Incorrect.

    Incorrect. A lack of an available patch does not mean the vulnerability is a false positive. If the vendor has acknowledged the issue, the finding is credible and should be treated as real. The misconception is confusing patch availability with vulnerability validity. Rescanning later without implementing mitigation would not address current risk.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam