← Back

19 Prioritization, Mitigation & Controls Practice Questions & Answers

Every Prioritization, Mitigation & Controls practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.

Start practice test →
  1. 1. A weekly scan returns two findings. Finding A is rated critical and sits on a lab server in an isolated segment with no inbound or outbound routing, used only for driver testing. Finding B is rated medium, affects the public web application that fronts the customer payment flow, and working exploit code for it is circulating publicly. Which finding is worked FIRST, and on what basis?

    • A.Finding A first: an isolated laboratory host is where unpatched software is most often attacked from inside.
    • B.Finding A first: a critical rating outranks a medium rating, so it is remediated ahead of other items.
    • C.Finding B first: it is reachable from the internet, exploit code exists, and payment data sits behind it.✓ Answer
    • D.Finding B first: medium items patch faster, so clearing them keeps the open-finding count falling.

    A severity rating describes how bad a flaw would be if it were exploited; it says nothing about whether anyone can reach it. Priority comes from reachability, evidence of exploitation and what the asset protects, so a medium finding on an internet-facing payment front end with public exploit code outranks a critical finding on a host that has no route in or out.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — Prioritize and mitigate vulnerabilities (context awareness: internal, external, isolated)Report a problem with this question

  2. 2. Two findings sit on internet-facing hosts and carry similar severity ratings. For the first, a national cyber-defence authority lists the underlying flaw in its catalogue of flaws confirmed to be exploited in ongoing attacks. For the second, no exploitation has been observed anywhere and only a theoretical write-up exists. What does that difference do to the order of work?

    • A.It lowers both findings, because a documented exploit means the detection tooling in place already blocks that attack path.
    • B.It changes nothing at all, because the order of remediation is set by the severity rating each finding already carries.
    • C.It moves the confirmed-exploited finding to the front, because in-the-wild attacks make compromise a present event, not a modelled one.✓ Answer
    • D.It moves the theoretical finding ahead, because an unstudied flaw carries more unknown risk than one attackers already use.

    Severity answers how bad the outcome would be; exploitation evidence answers how likely the outcome is right now. A flaw confirmed to be under active exploitation on a reachable host is being attacked today, so it is sequenced ahead of a similarly rated flaw that nobody has weaponised, and the existence of a public exploit never implies that detection already blocks it.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — scoring methods and context awareness; CISA Known Exploited Vulnerabilities catalogue (confirmed active exploitation)Report a problem with this question

  3. 3. Two findings carry the same severity rating on the same product. The first affects a management interface that listens only on a management VLAN reachable from two jump hosts, both requiring MFA, and the vendor patch is scheduled for the next maintenance window. The second affects that product's public API endpoint, with nothing restricting access to it. Which is worked FIRST, and how is the other one handled?

    • A.The public API endpoint first; the management interface keeps its documented access restriction until the window.✓ Answer
    • B.The management interface first; insiders abuse internal management paths more often than outsiders abuse public ones.
    • C.Both inside one emergency change; findings sharing a rating must be remediated together to keep counts aligned.
    • D.The public API endpoint first; the management interface finding can be closed now because access is already restricted.

    Identical ratings are separated by the access path an attacker would have to use. An unrestricted public endpoint is reachable by anyone, while a management interface sitting behind a segmented VLAN and MFA-protected jump hosts already has a compensating restriction in front of it. That restriction lowers urgency and justifies waiting for the window, but it does not remove the defect, so the second finding stays open until the patch is applied and verified.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — context awareness and compensating controlsReport a problem with this question

  4. 4. A scanner reports a high-severity flaw in a library bundled with a batch processing server. Developers confirm the vulnerable function is never called by the deployed code path, the library is present only as a transitive dependency, and no listener uses it. The same library is loaded and exposed by a customer-facing service owned by the same team. How should the two be sequenced?

    • A.Close the batch server finding as a false positive, because an unreachable function is not a real vulnerability at all.
    • B.Fix the batch server first, because a bundled library keeps spreading to more hosts as the product is deployed further.
    • C.Fix both in one emergency change, because a shared component means the exposure is identical on every host.
    • D.Fix the customer-facing service first and keep the batch server tracked as not currently reachable, with review.✓ Answer

    Reachability, not the presence of vulnerable bytes, drives the order: the exposed service can actually be driven into the vulnerable code, so it goes first. The batch server is still genuinely vulnerable code on disk and one refactor could make it reachable, so it is a risk-based deferral with a review date, not a false positive.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — prioritization by context awareness and exploitability, not by rating aloneReport a problem with this question

  5. 5. A legacy scheduling appliance carries an unpatchable finding: the vendor has ended support and the replacement project completes next year. The business cannot take the appliance out of service. Which handling is correct?

    • A.Restrict its reachability with tight ACLs, then record a time-boxed exception with a named owner and review date.✓ Answer
    • B.Record the finding as a false positive because no vendor patch exists, and drop the host from recurring scan scope.
    • C.Leave it open and untouched in the queue, because only a vendor patch can change the status of a scanner finding.
    • D.Accept the risk at analyst level and note in the ticket that no remediation path is available for the appliance.

    When no patch will ever arrive, the defensible path is to shrink the attack surface with a compensating control and then move the residual risk into a documented exception that a risk owner accepts for a limited time. Suppressing the finding or accepting it silently at analyst level removes the visibility and the accountability that make the deferral legitimate.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — mitigation strategies: compensating controls and exceptionsReport a problem with this question

  6. 6. A web application flaw cannot be patched for six weeks, so the team writes a blocking rule on the filtering layer in front of the application and confirms the rule stops the known attack request. The vulnerability manager asks what has actually changed. Which statement is accurate?

    • A.The finding may now be closed, because the tested attack request no longer reaches the application server at all.
    • B.The exploit path is blocked for now, but the defect is still in the code, so the finding stays open and the patch stays tracked.✓ Answer
    • C.The severity rating must be lowered permanently in the register, since the flaw can no longer be exploited today.
    • D.The flaw counts as fully remediated, so the patch can be dropped from the release plan for that application.

    A compensating control buys time by blocking a known path; it does not repair the vulnerable code, and an attacker who finds a request shape the rule does not match is back at the original defect. The finding therefore stays open with the control documented, and it closes only when the patch is applied and re-verified.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — compensating controls versus remediation; validating remediationReport a problem with this question

  7. 7. A finding concerns an optional file-preview feature in an internal document service. No business process uses the feature, the vendor's fix is two releases away, and switching the feature off is a supported configuration change. What is the appropriate action?

    • A.Take the whole document service out of production until the vendor ships a fix for the preview feature.
    • B.Wait for the vendor fix, because a configuration change never counts as remediation of a scanner finding.
    • C.Switch the unused feature off now as a configuration change, and patch when that release lands.✓ Answer
    • D.Request a permanent risk acceptance, because a feature that nobody uses cannot be reached by an attacker.

    Removing the vulnerable functionality is a legitimate remediation path, not a workaround: if the feature is not running, the code cannot be invoked, and the change is reversible and supported. Patching still follows for completeness, while an enabled-but-unused feature remains exploitable and cannot be waved away as unreachable.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — mitigation strategies: patching and configuration managementReport a problem with this question

  8. 8. A configuration hardening change was pushed to 300 servers by the endpoint management platform, which reported 300 successes, and the ticket closed automatically. The next authenticated scan still lists 46 of those servers as affected. What should the analyst conclude and do?

    • A.The finding is closed once 254 servers verify clean, because the rest falls inside expected configuration drift.
    • B.The platform's success report is the authoritative record, so the 46 scan results are treated as false positives.
    • C.The scan ran too soon after the change, so the right step is to suppress those 46 results for one full cycle.
    • D.Deployment reporting is not verification, so reopen the finding and drive the 46 remaining servers to a clean authenticated rescan.✓ Answer

    A finding is closed by evidence from the tool that reported it, not by the tool that pushed the change: an agent can report a successful push while a service restart, a policy conflict or a rollback leaves the setting ineffective. The authenticated rescan is the validation step, so the 46 disagreements are exceptions to chase until they verify clean.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — validating remediation (rescanning, audits and verification)Report a problem with this question

  9. 9. A kernel update closes an internal finding on the clustered database behind order capture. Applying it needs a rolling restart, the vendor notes a regression affecting one storage driver, the host is not internet-facing, and no exploitation of the flaw is reported. The next approved change window is in nine days. What is the defensible course?

    • A.Schedule it in the approved window with a rollback plan, then run a validation rescan after the change.✓ Answer
    • B.Apply the update tonight outside the window, because any open finding outranks operational scheduling.
    • C.Raise an emergency change and skip the rollback plan, so the maintenance outage stays as short as possible.
    • D.Accept the risk indefinitely, because the update carries a documented regression on one storage driver.

    The remediation carries its own risk, and here the finding is internal with no observed exploitation, so nothing justifies bypassing change control. The proportionate answer is the approved window, a rollback path for the known driver regression, and a rescan afterwards to prove the finding actually closed; an emergency change without rollback trades a modest risk for an outage risk on revenue-bearing systems.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — patching and configuration management within change control; validating remediationReport a problem with this question

  10. 10. Closing a finding requires disabling an older protocol version on a payment-adjacent server. Doing so breaks a supplier integration that cannot be changed for two quarters, and the organisation's own internal standard forbids that protocol version. The analyst cannot both comply with the standard and keep the integration running. What must the analyst do?

    • A.Leave the protocol enabled and record the supplier's business reason in the comment field of the scan ticket.
    • B.Escalate it as a formal policy exception for the risk owner to decide, with compensating controls, an expiry date and a review.✓ Answer
    • C.Disable the protocol in the next window and let the supplier integration fail until the supplier adapts.
    • D.Reclassify the finding as informational, because the internal standard cannot be met with today's integration.

    When remediation and a documented internal requirement cannot both be satisfied, the decision is no longer technical and is not the analyst's to make: it belongs to the risk owner through the exception process, which records the business justification, the compensating controls, an expiry and a review. Silently leaving the protocol on, or downgrading the finding, hides an accepted risk that the organisation never formally accepted.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — exceptions and compensating controls; Objective 2.4 — risk management and governance of accepted riskReport a problem with this question

  11. 11. Two externally reachable hosts carry the same finding with the same severity rating, and no exploitation has been observed. One is a marketing brochure site with static pages and no user accounts. The other is the portal clinicians use to retrieve patient records. Which is worked FIRST, and what decides it?

    • A.The clinician portal, because an authenticated application always carries a higher rating than an open one.
    • B.The brochure site, because a public site with no authentication gives an attacker the easiest first foothold.
    • C.Either one, because an identical rating and identical exposure leave nothing to separate the two findings.
    • D.The clinician portal, because what the asset does and the data behind it set the consequence of compromise.✓ Answer

    When exposure and rating match, asset criticality and data sensitivity break the tie: compromise of a static brochure site costs reputation, while compromise of a records portal reaches regulated patient data and a clinical workflow. The rating itself does not change because an application requires authentication; business context, not the score, moves the item to the front.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — context awareness: asset criticality and data sensitivity in prioritizationReport a problem with this question

  12. 12. A finding will stay open for a month while a patch is validated. The plan lists a firewall rule that blocks the vulnerable port, an alert that fires when that port is probed, a documented rebuild procedure if the host is compromised, and a monthly management review of the open item. Which item supplies the detective function, and what does that function contribute here?

    • A.The firewall rule, because blocking the vulnerable port produces the record that shows attempts against the host.
    • B.The probe alert, because it tells the team the blocked path is being tested while the defect is still present.✓ Answer
    • C.The rebuild procedure, because restoring the host reveals what an attacker changed while it was open.
    • D.The management review, because a monthly checkpoint uncovers findings that stayed open past their date.

    Blocking is a preventive function and rebuilding is a corrective one; only the alert observes activity and reports it while the vulnerability is still live, which is what tells the team whether the interim protection is being probed and whether the deferral is still safe. Management review is an administrative oversight step, not detection of attacker activity.

    Source: CompTIA CySA+ CS0-004, Objective 2.4 — control functions: preventative, detective, responsive/correctiveReport a problem with this question

  13. 13. A remediation plan for findings in a server room lists three items: a written standard requiring quarterly review of server images, a locked cabinet with a camera over the rack, and a host configuration baseline enforced by an agent. Classify the three items by the nature of the control, in the order listed.

    • A.The standard is administrative, the cabinet physical, the baseline technical.✓ Answer
    • B.The standard is technical, the cabinet administrative, and the baseline physical.
    • C.The standard is operational, the cabinet physical, the baseline managerial.
    • D.The standard is managerial, the cabinet technical, the baseline operational.

    Control nature is judged by what implements the control, not by who asked for it: a written requirement is carried out by people and procedure, a locked cabinet with a camera restricts and observes physical access, and an agent-enforced configuration baseline is implemented by technology. The operational and managerial labels belong to an older taxonomy and are not how these controls are classified now.

    Source: CompTIA CySA+ CS0-004, Objective 2.4 — control types: administrative (managerial), technical, physicalReport a problem with this question

  14. 14. A finding on a service hosted by a third party cannot be remediated by the organisation itself, and management points to a contract clause that makes the provider liable for breach costs. The analyst is asked whether the finding can be closed. Which answer is correct?

    • A.Yes: because liability now sits with the provider, the item can leave the organisation's register of open findings.
    • B.No: shifting who pays leaves the technical exposure in place, so the finding stays tracked with the provider's fix commitment.✓ Answer
    • C.Yes: findings on a hosted service belong to the provider's own scan scope and fall outside the analyst's tracking.
    • D.No: the contract clause has to be voided before any finding on a hosted service can be worked or reported.

    Transferring risk by contract or insurance moves the financial consequence, not the vulnerability: customers can still be harmed and the service can still be compromised. The analyst therefore keeps the finding in the register, records the provider's committed fix and dates, and reports the residual exposure, because only the provider's remediation and its verification can close it.

    Source: CompTIA CySA+ CS0-004, Objective 2.4 — risk management strategies (transfer) and third-party/supply chain riskReport a problem with this question

  15. 15. A segment that processes payment card data falls under an obligation the organisation inherited through its contract with the acquiring bank. A finding there was handled with a compensating control instead of a patch. What does the inherited obligation add to the analyst's work?

    • A.A mandatory severity increase on the finding, which the analyst enters by hand before the report is issued.
    • B.Nothing extra: an inherited obligation governs the external auditor's report rather than the vulnerability management record.
    • C.Evidence duties: the control, its approval, its scope and its review date must be recorded for external validation.✓ Answer
    • D.A duty to remove that segment from the scan scope so findings never appear in the compliance evidence pack.

    An inherited obligation does not change the technical decision, it changes what must be provable: a compensating control is acceptable only when someone can later show what it is, who approved it, exactly what it covers and when it will be revisited. That is why regulated or contractually bound scopes turn the analyst's notes into retained evidence rather than internal commentary.

    Source: CompTIA CySA+ CS0-004, Objective 2.4 — regulatory and compliance drivers of vulnerability management, compensating control documentationReport a problem with this question

  16. 16. Four findings are open. A: a high-rated flaw on an air-gapped test bench. B: a medium-rated authentication bypass on the internet-facing customer portal, with exploitation reported in the wild. C: a high-rated flaw on an internal print server whose vulnerable port is already blocked at the firewall. D: a critical-rated flaw on a spare server that is powered off pending decommission. Which is worked FIRST?

    • A.D, the critical-rated flaw on the powered-off spare, because critical items head the queue.
    • B.A, the flaw on the air-gapped test bench, because it carries a high severity rating.
    • C.B, the authentication bypass on the internet-facing portal with exploitation reported.✓ Answer
    • D.C, the print server flaw, because a high rating still outranks a medium one after blocking.

    Only one of the four combines a reachable attack path, an authentication bypass on a customer-facing service and evidence that attackers are using it now. The air-gapped bench has no path, the powered-off spare presents no running service to attack despite its rating, and the print server's path is already blocked, which is exactly why a lower rating can outrank higher ones.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — prioritization by exposure, exploitation evidence and existing controls rather than severity ratingReport a problem with this question

  17. 17. A finding on an internal reporting server was ranked low because the host sat on an internal segment only. A project has just published that server through an external gateway so partners can reach it, and the finding is still unpatched. What is the correct response?

    • A.Keep the original rank, because neither the severity rating nor the underlying flaw in the software has changed.
    • B.Re-rank the finding now that the host is externally reachable, treating the exposure change as the trigger.✓ Answer
    • C.Keep the original rank until the next scheduled scan cycle reports the finding from an outside view.
    • D.Lower the rank, because a gateway in front of the server means that gateway now owns the exposure.

    Priority is a function of the flaw and its environment, so a change in exposure re-opens the ranking even though the vulnerability itself is untouched. Waiting for the next scan leaves a now-reachable defect ranked on stale context, and a gateway only reduces exposure if it actually filters or terminates the vulnerable request, which publishing alone does not do.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — context awareness (internal, external, isolated) drives re-prioritizationReport a problem with this question

  18. 18. An unsupported medical imaging controller carries a serious finding that cannot be patched. The team moves it to a segment that permits only the imaging workstation's traffic and logs every other attempt. A manager asks whether the risk is now resolved. Which answer is accurate?

    • A.No: segmentation achieves nothing on an unsupported device, so the controller has to leave service now.
    • B.Yes: a segment that admits only one workstation removes the attack path entirely, so the finding can be closed.
    • C.Yes: logging every other attempt turns the finding into a detective control and closes out the exposure.
    • D.No: segmentation shrinks who can reach the flaw and buys monitored time, but the defect and the device replacement remain on plan.✓ Answer

    Segmentation is a compensating control: it narrows the set of hosts that can talk to the flaw and, with logging, gives the team warning if that narrow path is abused. It does not repair the device, and the permitted workstation is itself a route in if it is compromised, so the finding remains open with replacement tracked and the exception reviewed.

    Source: CompTIA CySA+ CS0-004, Objective 2.3 — mitigation via segmentation as a compensating control; residual risk remainsReport a problem with this question

  19. 19. A vulnerability register shows four entries for one quarter: the vendor patch applied and confirmed by rescan; the vulnerable service removed from the host entirely; a proxy rule filtering the exploit request while the patch waits; and the risk owner's documented decision to take no action, with a review date. Which entry is the compensating control?

    • A.The proxy rule filtering the exploit request while the vendor patch is still pending.✓ Answer
    • B.The vendor patch applied and then confirmed clean by the follow-up authenticated rescan.
    • C.The risk owner's documented decision to take no action, carrying a stated review date.
    • D.The removal of the vulnerable service from the host where it had been installed.

    A compensating control is an alternative measure used when the primary control cannot be applied yet, so the filtering rule standing in for the missing patch is the compensating entry. Patching and removing the service are remediation, because the vulnerable code is fixed or gone, and a documented decision to take no action is risk acceptance rather than a control at all.

    Source: CompTIA CySA+ CS0-004, Objective 2.4 — compensating control as an alternative when the primary control is unavailable; Objective 2.3 remediation and risk acceptanceReport a problem with this question

Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →