Security+ Lesson

Vulnerability Response And Remediation for Security+

Last updated: 6/10/2026

Short answer

The best response depends on what is vulnerable, how exposed it is, whether a fix exists, and how quickly the organization can act. Patching is the most direct response when a tested update is available and the asset can tolerate the change. Patching should still consider maintenance windows, dependencies, rollback options, and criticality, but the Security+ decision signal is simple: known vulnerability plus available update often points to patching.

Why it appears on the exam

SY0-701 4.3: Select response options such as patching, insurance, segmentation, compensating controls, exceptions, and exemptions.

Key concepts

Concept 1

Required terms

patching: applying a vendor or maintainer update to remove or reduce a vulnerability. insurance: transferring some financial impact of a security event to an insurance arrangement; it does not fix the technical vulnerability. segmentation: limiting network or system reachability so a vulnerable asset has reduced exposure or blast radius. compensating controls: alternate controls used when the preferred remediation is not immediately possible or sufficient.

Example

A vendor releases a security update for a vulnerable web server package. After testing, patching is the primary remediation.

Concept 2

How Vulnerability Response And Remediation works

The best response depends on what is vulnerable, how exposed it is, whether a fix exists, and how quickly the organization can act. Patching is the most direct response when a tested update is available and the asset can tolerate the change. Patching should still consider maintenance windows, dependencies, rollback options, and criticality, but the Security+ decision signal is simple: known vulnerability plus available update often points to patching.

Example

A legacy medical device cannot be patched without vendor recertification. Segmentation and strict access controls can reduce exposure while the organization tracks an exception.

Concept 3

Common confusion

Insurance is often overselected as if it fixes vulnerabilities. Insurance transfers some financial risk. Patching, segmentation, or compensating controls are the technical responses that change exposure or vulnerability state.

Example

An application flaw cannot be fixed until the next release. A web application filtering rule and added monitoring may serve as compensating controls.

Concept 4

What to recognize

Choose patching, segmentation, compensating controls, insurance, exception, or exemption based on constraints; Distinguish remediation from mitigation and risk transfer; Identify when temporary compensating controls need documentation and review; Choose segmentation when a vulnerable system cannot be patched but exposure can be limited.

Example

A low-risk internal system cannot meet a password rotation standard because it uses certificate-based service authentication. An exemption may be documented if the requirement truly does not apply.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.On the exam, this detail appears: A vendor releases a security update for a vulnerable web server package. After testing, patching is the primary remediation. Which answer matches it?

Q2.Read this Security+ situation: Cyber insurance may help absorb financial loss, but it does not close a CVE on an exposed server. What is the best match?

Q3.A security team needs to decide what this situation represents: A legacy medical device cannot be patched without vendor recertification. Segmentation and strict access controls can reduce exposure while the organization tracks an exception. Which option fits?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8