
CompTIACySA+
Domain 2Objective 5
Vulnerability Response CS0-003 Practice Questions (Page 5)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
9concepts
30%of the exam
Questions 21–25
- 21
A security team is threat modeling a new application that will handle sensitive customer data. The team has limited time and must prioritize threats. Which approach is most effective?
Select an answer first - 22
A security team is struggling to get business units to patch their systems on time. The team has no authority to enforce patching, and vulnerabilities remain unpatched for months. Management wants to improve compliance. Which action is most aligned with governance?
Select an answer first - 23
A security team must patch a critical vulnerability in a database server that supports a 24/7 customer-facing application. The patch requires a service restart, which will cause a 10-minute outage. The team has a change window from 2:00 AM to 4:00 AM on Sunday. What is the most appropriate action?
Select an answer first - 24
An organization defines a target that critical patches must be applied within 48 hours of release. This target is best described as a:
Select an answer first - 25
A security team must patch a critical vulnerability in a service that has an SLO of 99.99% availability. The patch requires a 10-minute restart. The service runs on two instances behind a load balancer. Which approach best meets the SLO?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.