A vulnerability scan finds a critical unpatched service on a legacy server that supports a revenue-critical application. The application owner states that applying the vendor patch will break production, and no safe workaround exists. What should the vulnerability analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of this like driving a truck that can't get new tires: you don't just ignore the flat, and you don't rip the axle out. You get a signed note saying the risk is accepted, then put cones and flares around it. In this case, that means formal risk acceptance plus compensating controls, not silent scope removal.
Full Explanation
Vulnerability prioritization is not only CVSS severity; it is severity plus exploitability plus business impact plus feasible remediation. When a critical patch is technically unavailable or would cause unacceptable operational harm, the accepted risk-management path is a documented exception or formal risk acceptance. That record should identify the vulnerability, business justification, owner approval, compensating controls such as segmentation, least-privilege access, virtual patching or enhanced monitoring, and a review date. This preserves accountability while reducing exposure. Forcing immediate remediation ignores business continuity and can create a larger incident by taking a business-critical service offline. Informal acceptance without compensating controls is not risk management because it leaves the exposure unmitigated and untracked. Removing the asset from scanning scope hides the finding instead of reducing risk and corrupts reporting. Exam caveat: choose the answer that documents approval and compensating controls, not the answer that simply lowers severity. Operational check: have the application owner sign the exception, then verify the compensating control is active in firewall policy or EDR monitoring before closing the ticket.