A legacy application server has a critical vulnerability, but patching breaks a vendor-supported workflow. The business asks for a risk acceptance so the server can remain online. The analyst proposes compensating controls such as network segmentation and virtual patching. What is the best way to document the vulnerability response?
Select an answer to reveal the explanation.
Short Explanation
Think of an exception like a borrowed tool: it needs a due date, or it becomes permanent. You approve the compensating controls, but you also set an expiration and review so the risk doesn't quietly outlive the business need. If you skip the clock, you've just traded a patch for an unmanaged waiver.
Full Explanation
Time-bound vulnerability exceptions keep risk acceptance from becoming permanent risk abandonment. The mechanism is formal risk acceptance: the business owner accepts residual risk, but the analyst requires compensating controls, an expiration date, and a scheduled review so the exception is revalidated as threat exposure, asset value, or technical debt changes. This aligns with vulnerability response governance because exceptions are temporary, not replacements for remediation. A permanent acceptance is wrong because compensating controls reduce or offset exposure; they do not remove the root vulnerability, and indefinite acceptance prevents revalidation. Removing findings from scan reporting is wrong because it destroys visibility and breaks the vulnerability management feedback loop, even if alert fatigue is a concern. Recording only an asset-inventory note without action is wrong because risk acceptance must be documented in the exception process and reviewed, not left as a passive inventory attribute. Exam caveat: CompTIA expects you to favor risk-acceptance governance over informal waivers, especially when compensating controls are involved. Operational check: confirm the exception ticket contains an owner, approved compensating controls, an expiration date, and a calendar review task.