Free CompTIA CySA+ CS0-003 Practice Question

During a routine vulnerability assessment, a security analyst uncovers several low to medium severity vulnerabilities on a development server not accessible from the internet and used solely by a few in-house software developers for testing new code. No sensitive information is processed or stored on this server. In guiding the remediation process, taking into account this server's function and connectivity, what should be the analyst's NEXT move?

  • Isolate the server from the internal network until all vulnerabilities are remediated.

  • Raise the priority of the vulnerabilities due to the server's critical role in product development.

  • Prioritize the patching lower than systems with internet-facing services or handling sensitive data.

  • Escalate to the incident response team immediately due to potential zero-day exploitation risks.

This question's topic:
CompTIA CySA+ CS0-003 / 
Vulnerability Management
Your Score:

Check or uncheck an objective to set which questions you will receive.