nerdexam
CompTIA

CAS-005 · Question #97

A company's security policy states that any publicly available server must be patched within 12 hours after a patch is released. A recent IIS zero-day vulnerability was discovered that affects all…

The correct answer is D. 4. Due to it having IIS installed and due to it being open externally with no WAF infront of it.

Submitted by carter_n· Mar 6, 2026Security Operations

Question

A company's security policy states that any publicly available server must be patched within 12 hours after a patch is released. A recent IIS zero-day vulnerability was discovered that affects all versions of the Windows Server OS:

Which of the following hosts should a security analyst patch first once a patch is available?

Exhibits

CAS-005 question #97 exhibit 1
CAS-005 question #97 exhibit 2

Options

  • A1
  • B2
  • C3
  • D4
  • E5
  • F6

How the community answered

(35 responses)
  • A
    11% (4)
  • B
    6% (2)
  • C
    23% (8)
  • D
    54% (19)
  • E
    3% (1)
  • F
    3% (1)

Explanation

Due to it having IIS installed and due to it being open externally with no WAF infront of it.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice