CS0-003 · Question #234
A new zero-day vulnerability was released. A security analyst is prioritizing which systems should receive deployment of compensating controls deployment first. The systems have been grouped into…
The correct answer is C. Group C. Zero-Day Vulnerability Prioritization Explanation Why Group C is correct: When prioritizing compensating controls for a zero-day vulnerability, the highest-priority systems are those that are both internet-facing (exposed) AND unpatched/unsupported - characteristics typically…
Question
A new zero-day vulnerability was released. A security analyst is prioritizing which systems should receive deployment of compensating controls deployment first. The systems have been grouped into the categories shown below:
Which of the following groups should be prioritized for compensating controls?
Exhibit
Options
- AGroup A
- BGroup B
- CGroup C
- DGroup D
How the community answered
(48 responses)- A2% (1)
- B15% (7)
- C77% (37)
- D6% (3)
Explanation
Zero-Day Vulnerability Prioritization Explanation
Why Group C is correct: When prioritizing compensating controls for a zero-day vulnerability, the highest-priority systems are those that are both internet-facing (exposed) AND unpatched/unsupported - characteristics typically associated with Group C. These systems present the greatest attack surface because they are reachable by threat actors and lack existing vendor patches or security updates to mitigate exploitation.
Why the distractors are wrong: Group A likely represents systems that are patched or have existing mitigations, reducing urgency. Group B may contain internal or isolated systems that, while unpatched, have limited exposure to external threats. Group D likely represents systems that are either already protected or have low criticality/low exposure, making them lower priority for immediate compensating controls.
Memory Tip: Think "Exposed + Unprotected = Emergency" - prioritize systems that face the outside world AND lack current defenses. A system hidden behind a firewall with no internet exposure is far less urgent than one directly accessible to attackers with no patch available. When in doubt, ask: "Can an attacker reach it, and does it have any existing protection?" - the answer drives your priority order.
Note: Since the actual table/groupings weren't provided, this explanation is based on standard CompTIA security prioritization principles. Review your specific table to confirm Group C matches high-exposure, unpatched systems.
Topics
Community Discussion
No community discussion yet for this question.
