Skip to content
CS0-003
Vulnerability Management
medium
Question 5 of 27

A vulnerability scanner reports a critical CVE on a server, but the organization's security team determines the vulnerable component is not reachable from any network segment. How should this finding be treated?

AAs an accepted risk with compensating control documentation, because network isolation reduces exploitability
BAs a false positive, because unreachable vulnerabilities do not exist
CAs the highest priority for immediate patching regardless of reachability
DAs a finding to be removed permanently from future scan reports

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion