nerdexam
CompTIA

CS0-003 · Question #20

The Chief Executive Officer of an organization recently heard that exploitation of new attacks in the industry was happening approximately 45 days after a patch was released. Which of the following…

The correct answer is A. A mean time to remediate of 30 days. A mean time to remediate of 30 days implies that the organization aims to remediate vulnerabilities within 30 days of their discovery. Since exploitation of new attacks tends to occur approximately 45 days after a patch is released, aiming for a mean time to remediate of 30…

Submitted by priya_blr· Mar 6, 2026Vulnerability Management

Question

The Chief Executive Officer of an organization recently heard that exploitation of new attacks in the industry was happening approximately 45 days after a patch was released. Which of the following would best protect this organization?

Options

  • AA mean time to remediate of 30 days
  • BA mean time to detect of 45 days
  • CA mean time to respond of 15 days
  • DThird-party application testing

How the community answered

(21 responses)
  • A
    81% (17)
  • B
    5% (1)
  • C
    10% (2)
  • D
    5% (1)

Explanation

A mean time to remediate of 30 days implies that the organization aims to remediate vulnerabilities within 30 days of their discovery. Since exploitation of new attacks tends to occur approximately 45 days after a patch is released, aiming for a mean time to remediate of 30 days ensures that vulnerabilities are patched before attackers have the opportunity to exploit them.

Topics

#Vulnerability remediation#Patch management#Mean Time To Remediate (MTTR)#Security metrics

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice