CompTIA CySA+ CS0-003 Practice Question

Your company has a contract with an external vendor that mandates critical vulnerabilities to be fixed within 48 hours of detection. A critical vulnerability was detected on a server managed by this vendor, but after 48 hours, there is no evidence that the issue has been addressed. What should be your first course of action?

  • You selected this option

    Review the terms of the contract regarding compliance criteria and communicate the breach to the vendor.

  • You selected this option

    Notify internal stakeholders about the failure to address the vulnerability.

  • You selected this option

    Escalate the issue to higher management within your company.

  • You selected this option

    Seek legal advice to address the vendor's non-compliance.

CompTIA CySA+ CS0-003
Reporting and Communication
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot