An internet-facing web application has a CVSS 9.1 vulnerability. The vulnerability scanner cannot confirm exploitability, but the WAF has a virtual patch blocking known exploit traffic. How should the analyst adjust risk priority?
Select an answer to reveal the explanation.
Short Explanation
Think of a WAF virtual patch like a temporary shield: it doesn't fix the hole, but it can stop the known attacker. You lower the immediate patch priority only when that shield is proven effective, then keep the underlying vulnerability on the radar.
Full Explanation
A compensating control changes effective risk, not the raw vulnerability score. CVSS describes intrinsic severity, but risk prioritization should combine threat exposure, asset value, and controls that reduce likelihood or impact. When a WAF virtual patch is active, tested, and blocking known exploit traffic, the analyst can lower immediate remediation priority while still tracking the finding until a permanent fix is deployed. A recommendation to keep the same high priority ignores that operational controls can materially reduce exploitability and can waste scarce remediation capacity. Raising the priority solely because the asset is internet-facing also misses the point; internet exposure is already a factor, but an effective WAF rule offsets some of that exposure. Permanently suppressing the finding is wrong because the vulnerability remains present, WAF rules can be bypassed, misconfigured, or fail open, and patching is still required. Exam caveat: CompTIA expects you to distinguish intrinsic severity from adjusted risk when a compensating control is documented and validated. Operational check: confirm the WAF rule is enabled, matches the vulnerable endpoint and attack pattern, and has logged blocked attempts before lowering the finding's priority.