CompTIA CySA+ CS0-003 (V3) Practice Question

A manufacturing company's security team discovers a critical remote code execution (RCE) vulnerability in a legacy industrial control system (ICS). The vendor's patch is available, but applying it will break the proprietary software, causing a lengthy production outage. The business has accepted the risk of not patching. Which of the following would be the MOST appropriate compensating control for the security analyst to recommend?

  • Implement network segmentation to place the ICS on an isolated network, and use a firewall to strictly limit all inbound and outbound connections to only those that are absolutely necessary.

  • Develop a business case to procure a new, modern ICS that will replace the legacy system within the next two fiscal years.

  • Install an Endpoint Detection and Response (EDR) agent on the legacy ICS to provide continuous monitoring and block malicious activity.

  • Formally document the patching exception in the organization's risk register and schedule a new risk assessment for the following quarter.

CompTIA CySA+ CS0-003 (V3)
Reporting and Communication
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot