What Must Be Done Before Mitigating Production Vulnerabilities?
Which of the following steps should be taken before mitigating a vulnerability in a production server?
Community Votes
55% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests whether you distinguish between vulnerability prioritization and the mandatory procedural safeguards required before deploying any production change.
This question evaluates understanding of operational procedures before modifying live systems, with community consensus favoring formal change control over technical analysis.
Candidates often choose risk assessment, mistakenly believing that classifying severity replaces the need for formal approval, testing, and rollback planning before touching a production server.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Core Concept
In enterprise IT operations, change management is the formalized process used to ensure that modifications to systems—especially production servers—are planned, tested, approved, and documented before implementation. When a vulnerability is discovered, the technical fix (patch, configuration change, or workaround) is considered a system change. Therefore, before mitigation begins, administrators must consult the organization’s change management policy.Why Option D is Correct
CompTIA Security+ consistently emphasizes that any alteration to a live production environment requires strict adherence to change control procedures. Implementing a mitigation without going through change management can lead to unexpected downtime, service disruption, misconfiguration, or failed patches. The change management process ensures the fix is evaluated for business impact, scheduled during maintenance windows, tested in a staging environment, approved by stakeholders, and accompanied by a rollback plan.Why the Other Options Are Incorrect
- Option A (SDLC team): The Software Development Life Cycle applies to building new applications, not patching or securing existing production infrastructure.
- Option B (IR plan): Incident Response is triggered when a security breach or active threat occurs. Discovering a vulnerability is a routine operational task, not an incident requiring emergency response.
- Option C (Risk assessment): While risk assessment and vulnerability scoring (e.g., CVSS) are essential for prioritizing which flaws to address first, they do not replace the procedural safeguards required before deploying changes to production. As noted by community experts, risk classification happens earlier in the vulnerability management lifecycle; change management is the immediate prerequisite for mitigation execution.
Community Consensus & Exam Tips
The split vote reflects a common test-taking trap: confusing the analysis phase with the execution phase. CompTIA rewards process-aware answers. Whenever you see “production,” “live,” or “deployment,” prioritize change management over technical analysis steps.Official Reference
- CompTIA Security+ SY0-701 Official Study Guide – Change Management & Vulnerability Management
- NIST Special Publication 800-40 Rev. 4 – Guide to Enterprise Patch Management Technologies
Exam Strategy
When a question involves deploying fixes, updates, or configurations to a live environment, immediately prioritize change management processes. Look for options mentioning approval, testing, rollback plans, and documentation rather than technical analysis steps. Always separate the identification/prioritization phase from the implementation phase in your mind.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →