exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 253 discussion

Actual exam question from CompTIA's CS0-003
Question #: 253
Topic #: 1
[All CS0-003 Questions]

Chief Information Security Officer (CISO) wants to disable a functionality on a business-critical web application that is vulnerable to RCE in order to maintain the minimum risk level with minimal increased cost. Which of the following risk treatments best describes what the CISO is looking for?

  • A. Transfer
  • B. Mitigate
  • C. Accept
  • D. Avoid
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CountVlad
Highly Voted 6 months, 2 weeks ago
Selected Answer: B
Mitigate involves taking steps to reduce the risk to an acceptable level. In this case, the CISO wants to disable a functionality that is vulnerable to Remote Code Execution (RCE) to reduce the risk associated with that vulnerability. Avoiding risk involves completely eliminating the risk by discontinuing the activity that introduces the risk. While disabling the functionality might seem like avoiding, in the context of risk management, avoiding would typically mean ceasing the use of the entire application or process, which is not the intent here.
upvoted 16 times
Jay2021aws
4 months, 1 week ago
Yes it is!
upvoted 1 times
...
...
LB54
Highly Voted 5 months, 3 weeks ago
Selected Answer: D
Risk avoidance involves taking actions to eliminate the risk entirely, which in this case means disabling the vulnerable functionality to prevent the risk of Remote Code Execution (RCE). This approach ensures that the risk is not present, aligning with the CISO’s objective of maintaining minimal risk.
upvoted 12 times
whoamyou
3 months, 2 weeks ago
Avoiding risk in this case would mean shutting down the web-application to bring the risk to zero and using a new solution, which would increases costs, and the question states 'with minimal increased cost.' Since the question also mentions 'maintaining the minimum risk level,' it implies that risk mitigation is being applied by disabling functionality.
upvoted 1 times
...
...
Popeyes_Chicken
Most Recent 1 day, 8 hours ago
Selected Answer: D
This is a clear example of risk avoidance. You're eliminating the risk altogether, not mitigating it. Mitigation also implies added cost or resources. As well as possible compensating controls that don't completely fix the vulnerability.
upvoted 1 times
...
ruelgo
5 days, 13 hours ago
Selected Answer: D
Avoiding risk means completely removing the threat by disabling or stopping the risky function. Since the CISO wants to disable the vulnerable part of the application, this is clearly a risk avoidance strategy. Mitigate means reducing the risk but keeping the functionality (like patching or adding more security).
upvoted 1 times
...
Learner213
1 month, 1 week ago
Selected Answer: B
It's Mitigate. I wanted to say avoid but, the question states "maintain the minimum risk level", not "eliminate" the risk level. Also, there are, likely, other ways to exploit the server with RCE but, I'm interjecting now.
upvoted 2 times
...
Aziz132
1 month, 3 weeks ago
Selected Answer: B
Disabling a vulnerable feature within a larger application does reduce or even eliminate the specific risk associated with that feature, but it does not mean the entire application or system is free from risk. This action specifically mitigates the risk tied to the Remote Code Execution (RCE) vulnerability in that feature, but the application itself remains in use and may still have other risks.
upvoted 1 times
...
cy_analyst
2 months, 3 weeks ago
Selected Answer: B
The correct is mitigate because even disabling part of the web app some risk remains.
upvoted 1 times
...
kinny4000
3 months, 1 week ago
Selected Answer: D
Key work: "DISABLE", this is risk avoidance. It's the least risky option, the question also stated for the "minimum risk level". Avoidance is always the least risky.
upvoted 2 times
...
SH_
3 months, 2 weeks ago
Selected Answer: B
Avoiding will be shutting down the web server. So I'll go with B, mitigating.
upvoted 3 times
...
SH_
3 months, 3 weeks ago
if only the functionality itself is vulnerable to RCE, and is disabled, then D would be appropriate. But if the functionality + web app are together vulnerable to RCE (say CVE chaining), and only the functionality is disabled, then B would be appropriate. So which is it?
upvoted 1 times
...
maggie22
4 months ago
Selected Answer: B
if you analyze the question deeply the answer will be B
upvoted 1 times
...
Wole_excel
4 months, 2 weeks ago
D. Avoid In this context, "avoid" refers to disabling the vulnerable functionality to eliminate the risk associated with remote code execution (RCE) vulnerabilities. By removing or disabling the specific feature that poses the risk, the CISO is aiming to avoid the potential security issue altogether while maintaining the overall risk level at a minimum with minimal cost.Mitigation involves implementing controls or changes to reduce the risk associated with a vulnerability. If the CISO is making modifications to the functionality to reduce the risk of RCE (e.g., by applying a partial fix or implementing additional security measures), then mitigation would be the appropriate term. However, if the functionality is entirely disabled to completely remove the associated risk, then avoid would be a more precise description. The key distinction is that avoidance involves eliminating the risk source altogether, whereas mitigation involves reducing the risk but not necessarily removing it entirely.
upvoted 2 times
...
voiddraco
4 months, 3 weeks ago
The Answer is B: “ in order to maintain the minimum risk level with minimal increased cost” if they were trying to avoid it they won’t be trying to maintain it the minimal risk level.
upvoted 2 times
...
lowkeycowboysfan
6 months, 1 week ago
Selected Answer: B
Key word on the question "maintain minimum risk level". Doesn't say avoid completely.
upvoted 7 times
kinny4000
3 months, 1 week ago
Minimum risk level would be to avoid the risk entirely (disable a risky functionality). Mitigation involves lowering risk to an acceptable point. If you disable the functionality, you've eliminated that specific risk, not mitigated.
upvoted 1 times
...
...
boog
6 months, 1 week ago
Another terrible question. B & D could be correct
upvoted 4 times
...
Rifandy
6 months, 2 weeks ago
Selected Answer: D
disabling just one function meaning ciso wants to avoid the risk
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago