What Must Be Done Before Mitigating Production Vulnerabilities?

Which of the following steps should be taken before mitigating a vulnerability in a production server?

  1. Escalate the issue to the SDLC team.
  2. Use the IR plan to evaluate the changes.
  3. Perform a risk assessment to classify the vulnerability.
  4. Refer to the change management policy. Source Reference Answer

Community Votes

D
55%
C
45%

55% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests whether you distinguish between vulnerability prioritization and the mandatory procedural safeguards required before deploying any production change.

This question evaluates understanding of operational procedures before modifying live systems, with community consensus favoring formal change control over technical analysis.

Candidates often choose risk assessment, mistakenly believing that classifying severity replaces the need for formal approval, testing, and rollback planning before touching a production server.

Community Discussion (4 comments)

9149f41 👍 5 Selected: C
The correct answer is C. Perform a risk assessment to classify the vulnerability. Before mitigating a vulnerability in a production server, it's crucial to perform a risk assessment to understand the potential impact and severity of the vulnerability. This helps in prioritizing the mitigation efforts and ensuring that the most critical vulnerabilities are addressed first.
Konversation 👍 3 Selected: D
Based on the style of this question with focus on "production server", the kind of answers referring to "software development" or "incident response plan", and similar questions by compTIA, where they ask for scheduled downtimes, I would go with answer D.
test_arrow 👍 1 Selected: D
Should be D Explanation: ✔ Ensures that changes are properly documented, tested, and approved before implementation. ✔ Prevents unintended downtime or issues by evaluating the impact of the mitigation on the production environment. ✔ Aligns with best practices for system stability and compliance.
9149f41 👍 2 Selected: D
A is not correct; there is no point to escalate vulnerability and mitigation. No incidents occur here. Vulnerability may be discovered by SIEM tools. B is not correct, because there is no incident occurring, just a vulnerability found that requires mitigation. C is not correct, because during mitigation there is no point to perform risk assessment.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Core Concept

In enterprise IT operations, change management is the formalized process used to ensure that modifications to systems—especially production servers—are planned, tested, approved, and documented before implementation. When a vulnerability is discovered, the technical fix (patch, configuration change, or workaround) is considered a system change. Therefore, before mitigation begins, administrators must consult the organization’s change management policy.

Why Option D is Correct

CompTIA Security+ consistently emphasizes that any alteration to a live production environment requires strict adherence to change control procedures. Implementing a mitigation without going through change management can lead to unexpected downtime, service disruption, misconfiguration, or failed patches. The change management process ensures the fix is evaluated for business impact, scheduled during maintenance windows, tested in a staging environment, approved by stakeholders, and accompanied by a rollback plan.

Why the Other Options Are Incorrect

  • Option A (SDLC team): The Software Development Life Cycle applies to building new applications, not patching or securing existing production infrastructure.
  • Option B (IR plan): Incident Response is triggered when a security breach or active threat occurs. Discovering a vulnerability is a routine operational task, not an incident requiring emergency response.
  • Option C (Risk assessment): While risk assessment and vulnerability scoring (e.g., CVSS) are essential for prioritizing which flaws to address first, they do not replace the procedural safeguards required before deploying changes to production. As noted by community experts, risk classification happens earlier in the vulnerability management lifecycle; change management is the immediate prerequisite for mitigation execution.

Community Consensus & Exam Tips

The split vote reflects a common test-taking trap: confusing the analysis phase with the execution phase. CompTIA rewards process-aware answers. Whenever you see “production,” “live,” or “deployment,” prioritize change management over technical analysis steps.

Official Reference

  • CompTIA Security+ SY0-701 Official Study Guide – Change Management & Vulnerability Management
  • NIST Special Publication 800-40 Rev. 4 – Guide to Enterprise Patch Management Technologies

Exam Strategy

When a question involves deploying fixes, updates, or configurations to a live environment, immediately prioritize change management processes. Look for options mentioning approval, testing, rollback plans, and documentation rather than technical analysis steps. Always separate the identification/prioritization phase from the implementation phase in your mind.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide