nerdexam
CompTIA

SY0-501 · Question #381

A security analyst is inspecting the results of a recent internal vulnerability scan that was performed against intranet services. The scan reports include the following critical-rated vulnerability:

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #381. The question stem and answer options stay visible for context.

Submitted by sofia.br· Mar 4, 2026Security operations

Question

A security analyst is inspecting the results of a recent internal vulnerability scan that was performed against intranet services. The scan reports include the following critical-rated vulnerability:

Title: Remote Command Execution vulnerability in web server Rating: Critical (CVSS 10.0) Threat actor: any remote user of the web server Confidence: certain Recommendation: apply vendor patches Which of the following actions should the security analyst perform FIRST?

Options

  • AEscalate the issue to senior management.
  • BApply organizational context to the risk rating.
  • COrganize for urgent out-of-cycle patching.
  • DExploit the server to check whether it is a false positive.

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#vulnerability management#CVSS#risk context#patch prioritization
Full SY0-501 Practice