nerdexam
CompTIA

CS0-003 · Question #646

A security analyst IS comparing the results of the past and current active credentialed vulnerability scans: Past scan: Current scan: Which of the following should the analyst do next?

The correct answer is B. Inform management about the risk that the company's assets will be used to perform attacks. The current scan shows that a previously low-severity SSL vulnerability has increased to a high- severity (9.1) issue with potential information disclosure. This means the organization now faces a significantly greater risk than before. Management must be informed because the…

Submitted by yaw92· Mar 6, 2026Vulnerability Management

Question

A security analyst IS comparing the results of the past and current active credentialed vulnerability scans:

Past scan:

Current scan:

Which of the following should the analyst do next?

Exhibits

CS0-003 question #646 exhibit 1
CS0-003 question #646 exhibit 2

Options

  • ATry to avoid a data leak by immediately creating a self-signed TLS certificate to patch the NTP
  • BInform management about the risk that the company's assets will be used to perform attacks.
  • CCreate a new entry on the risk register saying that all significant risks have been mitigated.
  • DRequest an unauthenticated scan to confirm that vulnerabilities have been patched.

How the community answered

(44 responses)
  • A
    9% (4)
  • B
    50% (22)
  • C
    27% (12)
  • D
    14% (6)

Explanation

The current scan shows that a previously low-severity SSL vulnerability has increased to a high- severity (9.1) issue with potential information disclosure. This means the organization now faces a significantly greater risk than before. Management must be informed because the company's assets could be leveraged in attacks or suffer data exposure, and leadership needs awareness to prioritize remediation.

Topics

#vulnerability scanning#risk reporting#remediation validation#management communication

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice