Free CompTIA CySA+ CS0-003 Practice Question

During a recent vulnerability assessment, it was discovered that a business-critical legacy application is vulnerable to a well-known security exploit. The application is running on an unsupported operating system, and the vendor no longer provides patches. As part of vulnerability management reporting, what should be the primary recommendation to stakeholders to mitigate the risk associated with this legacy application?

  • Decommission the application immediately to remove the vulnerability

  • Ignore the vulnerability since the application is business-critical

  • Upgrade the operating system to the latest version

  • Implement compensating controls to mitigate the risk

This question's topic:
CompTIA CySA+ CS0-003 / 
Reporting and Communication
Your Score:

Check or uncheck an objective to set which questions you will receive.