Skip to content
SY0-701
Threats, Vulnerabilities, and Mitigations
hard
Question 2 of 22

A security analyst observes that a newly discovered vulnerability in a widely used library has no available patch from the vendor. The organization relies on this library in a customer-facing application. Which mitigation technique should be applied FIRST?

ARemove the application from service immediately
BApply a compensating control such as a WAF rule or network segmentation while monitoring for vendor patch availability
CWait for the vendor to release a patch before taking any action
DPerform a penetration test to assess exploitability

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion