CompTIA CySA+ CS0-003 Practice Question
After reviewing a vulnerability management report, a security analyst needs to recommend an action plan to address critical vulnerabilities. Which of the following should be the analyst’s FIRST recommendation?
Reevaluate the existing business requirements to align with the current threat landscape.
Develop and deploy patches to remediate the identified critical vulnerabilities.
Implement compensating controls to temporarily mitigate risk until patches can be applied.
Conduct awareness, education, and training programs for the affected departments.