nerdexam
CompTIA

SY0-501 · Question #551

Several workstations on a network are found to be on OS versions that are vulnerable to a specific attack. Which of the following is considered to be a corrective action to combat this vulnerability?

The correct answer is D. Install a vendor-supplied patch. To address OS versions vulnerable to a specific attack, the most direct and effective corrective action is to apply vendor-supplied patches that fix the identified flaws.

Submitted by lukas.cz· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

Several workstations on a network are found to be on OS versions that are vulnerable to a specific attack. Which of the following is considered to be a corrective action to combat this vulnerability?

Options

  • AInstall an antivirus definition patch
  • BEducate the workstation users
  • CLeverage server isolation
  • DInstall a vendor-supplied patch
  • EInstall an intrusion detection system

How the community answered

(42 responses)
  • A
    14% (6)
  • B
    2% (1)
  • C
    7% (3)
  • D
    74% (31)
  • E
    2% (1)

Why each option

To address OS versions vulnerable to a specific attack, the most direct and effective corrective action is to apply vendor-supplied patches that fix the identified flaws.

AInstall an antivirus definition patch

Installing an antivirus definition patch updates the antivirus software's ability to detect malware, but it does not fix underlying operating system vulnerabilities.

BEducate the workstation users

Educating workstation users helps prevent them from contributing to security incidents or falling for social engineering, but it does not directly fix a technical vulnerability in the operating system itself.

CLeverage server isolation

Leveraging server isolation helps segment network resources and protect servers, but it does not address or fix vulnerabilities present on workstation operating system versions.

DInstall a vendor-supplied patchCorrect

Installing a vendor-supplied patch is the direct technical solution for an identified OS vulnerability, as vendors release these patches specifically to fix known security flaws and eliminate the vulnerability from the system's codebase.

EInstall an intrusion detection system

Installing an intrusion detection system (IDS) detects malicious activity or exploitation attempts, but it does not remove or fix the underlying OS vulnerability itself; it is a monitoring tool, not a corrective patch.

Concept tested: OS patching for vulnerability management

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-security-updates

Topics

#patch management#vulnerability remediation#corrective controls#OS patching

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice