SY0-701 exam dumps

SY0-701 practice question 294 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 294

Single answer4.3 Explain various activities associated with vulnerability management.

A security analyst runs a credentialed vulnerability scan against a group of internet-facing Linux web servers and finds a critical OpenSSL vulnerability with a published CVE and active exploitation in the wild. The scan report recommends an immediate patch. However, the operations team explains that the affected servers host a revenue-generating application that cannot tolerate unplanned downtime during business hours. The organization has a formal change-management process and a risk register. Which action should the analyst recommend FIRST to align with vulnerability management best practices?

  1. A

    Open an emergency change request, document the business risk, and coordinate remediation in the next approved maintenance window or under emergency approval if justified

  2. B

    Suppress the finding in the vulnerability scanner because the patch cannot be applied immediately and rescan after the next quarterly maintenance cycle

  3. C

    Accept the scanner's recommendation at face value and instruct the operations team to patch the servers immediately without change approval

  4. D

    Decommission the affected servers and rebuild them from backups after verifying that the vulnerability is exploitable

Show answer and explanation

Correct answer: A

Explanation

This question focuses on vulnerability management activities beyond simple scanning. A mature process includes discovery, validation, prioritization, risk assessment, change management, remediation, verification, and documentation of exceptions or accepted risk. In this scenario, the key facts are that the vulnerability is critical, associated with a CVE, internet-facing, and reportedly under active exploitation, all of which increase urgency. At the same time, production downtime must be controlled. Best practice is to route remediation through formal change management, using emergency procedures when justified, and to document the risk in the organization's tracking and governance processes.

This aligns with common guidance from NIST, including vulnerability management and risk management practices such as prioritizing based on exploitability, asset criticality, and business impact, then coordinating remediation through approved operational processes. If remediation cannot be immediate, compensating controls, temporary mitigations, or documented risk acceptance may be used, but the finding should remain visible and tracked until resolved or formally accepted.

  • A. Correct.

    Correct. Vulnerability management is not just identifying vulnerabilities; it includes validation, prioritization, risk analysis, exception handling, and remediation through established operational processes. Because the vulnerability is critical, internet-facing, and actively exploited, the analyst should escalate appropriately, document the risk, and use the organization's change-management process to pursue the fastest safe remediation path. In many organizations, that means an emergency change request or expedited maintenance window. This balances security urgency with operational stability.

  • B. Incorrect.

    Incorrect. Suppressing or ignoring a confirmed critical finding simply because remediation cannot occur immediately is poor vulnerability management. If the organization cannot patch right away, the issue should be tracked formally through risk acceptance, compensating controls, or scheduled remediation, not hidden from reporting. Suppression without governance creates blind spots and undermines accountability.

  • C. Incorrect.

    Incorrect. Even when a vulnerability is severe, bypassing formal change control can create outages, failed deployments, and accountability problems. Security+ emphasizes that remediation should follow organizational procedures, especially in production environments. The urgency may justify emergency change handling, but not unmanaged patching outside established governance.

  • D. Incorrect.

    Incorrect. Rebuilding or decommissioning systems is not the first or most practical response in this scenario. While rebuilding may be appropriate in some incident-response or lifecycle situations, vulnerability management normally starts with risk-based remediation planning. The prompt does not indicate compromise, only vulnerability exposure, so immediate decommissioning would be unnecessarily disruptive.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam