nerdexam
CompTIA

CS0-003 · Question #411

Several critical bugs were identified during a vulnerability scan. The SLA risk requirement is that all critical vulnerabilities should be patched within 24 hours. After sending a notification to…

The correct answer is C. Update the risk register and request a change to the SLA. When a patch cannot be deployed due to conflicting routine system upgrades, updating the risk register and requesting a change to the Service Level Agreement (SLA) is a practical approach. It allows for re-evaluation of the risk and adjustment of the SLA to reflect the current…

Submitted by jakub_pl· Mar 6, 2026Vulnerability Management

Question

Several critical bugs were identified during a vulnerability scan. The SLA risk requirement is that all critical vulnerabilities should be patched within 24 hours. After sending a notification to the asset owners, the patch cannot be deployed due to planned, routine system upgrades. Which of the following is the best method to remediate the bugs?

Options

  • AReschedule the upgrade and deploy the patch
  • BRequest an exception to exclude the patch from installation
  • CUpdate the risk register and request a change to the SLA
  • DNotify the incident response team and rerun the vulnerability scan

How the community answered

(12 responses)
  • A
    33% (4)
  • B
    8% (1)
  • C
    50% (6)
  • D
    8% (1)

Explanation

When a patch cannot be deployed due to conflicting routine system upgrades, updating the risk register and requesting a change to the Service Level Agreement (SLA) is a practical approach. It allows for re-evaluation of the risk and adjustment of the SLA to reflect the current situation.

Topics

#Vulnerability remediation#Risk management#SLA#Change management

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice