SY0-701 exam dumps

SY0-701 practice question 295 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 295

Single answer4.3 Explain various activities associated with vulnerability management.

A security analyst runs a credentialed vulnerability scan against a group of internet-facing Linux web servers and finds a critical OpenSSL vulnerability with a published vendor patch. The servers process customer transactions and have a strict uptime requirement. The operations team says they cannot patch immediately because a major sales event starts tomorrow. Which action should the analyst recommend FIRST as part of a sound vulnerability management process?

  1. A

    Document the risk, implement temporary compensating controls such as restricting access paths or increasing monitoring, and schedule patching through change management as soon as the maintenance window opens

  2. B

    Ignore the finding until the next scheduled quarterly scan because patching during a business event could disrupt availability

  3. C

    Immediately uninstall OpenSSL from the affected servers to eliminate the vulnerability, even if the web applications stop working

  4. D

    Mark the finding as a false positive because the scan was performed with credentials and internet-facing systems often trigger noisy results

Show answer and explanation

Correct answer: A

Explanation

This scenario tests practical vulnerability management, not just knowledge of patching. A mature process includes identification through scanning, validation of findings, prioritization based on factors such as asset criticality, exposure, exploitability, and business impact, then treatment through remediation, mitigation, acceptance, or exception handling. Because these are internet-facing transaction systems with a critical vulnerability and immediate patching is operationally constrained, the most appropriate first recommendation is to formally document the risk, apply compensating controls, and schedule remediation through change management as soon as feasible. This aligns with common guidance from NIST vulnerability management and risk management practices, including prioritizing based on business context and using temporary mitigations when immediate remediation is not practical. It also reflects industry best practices such as maintaining remediation timelines for critical issues, tracking exceptions, and validating fixes after implementation with rescanning.

  • A. Correct.

    This is the best answer because vulnerability management is risk-based and operationally aware. When a validated critical vulnerability exists and immediate remediation is not possible, the correct next step is to document the risk, apply compensating controls, and move the fix through the organization's change management process at the earliest safe opportunity. Examples include limiting inbound access to required sources, deploying or tuning WAF rules, increasing logging and alerting, and tightening segmentation. This reflects standard vulnerability treatment options: remediate when possible, mitigate temporarily when necessary, and track the exception until closure.

  • B. Incorrect.

    This is incorrect because delaying action until the next quarterly scan ignores an identified critical vulnerability on a high-value public-facing asset. Vulnerability management is not just about scanning cadence; it includes analysis, prioritization, remediation, mitigation, and exception handling. A major business event may justify delaying the patch briefly, but not doing nothing. The organization should implement short-term safeguards and formally track the risk.

  • C. Incorrect.

    This is incorrect because it is an overly disruptive response that does not align with business requirements or change control. OpenSSL is commonly required for TLS functionality on web servers, so uninstalling it could cause an outage and break customer transactions. Vulnerability management aims to reduce risk while balancing availability, integrity, and confidentiality. Emergency removal of a core component without impact analysis is not the best first recommendation here.

  • D. Incorrect.

    This is incorrect because a credentialed scan generally provides better visibility and reduces, rather than increases, false positives. Although findings should be validated as needed, there is no indication in the scenario that this result is erroneous. In fact, the presence of a published vendor patch strengthens confidence that the issue is real. Labeling a serious finding as a false positive without evidence is a common but dangerous mistake.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam