A vulnerability scan reports a critical CVE on a legacy imaging server that cannot be patched without breaking vendor support. The change board denies the emergency patch window. What should the analyst communicate to stakeholders?
Select an answer to reveal the explanation.
Short Explanation
Think of an unpatched legacy system like a leaky roof you can't replace until spring: you put a tarp over it and say so. In your report, that tarp is the compensating control, and the remaining leak is the residual risk. Don't hide the leak by closing or delaying the finding; document why it can't be patched and what you're doing to manage it.
Full Explanation
When patching is not feasible, vulnerability management reporting must still preserve risk visibility by explaining why the finding remains open and what controls reduce likelihood or impact. Compensating controls such as segmentation, host hardening, restricted access, monitoring, or virtual patching are communicated with residual risk so leadership can make an informed acceptance decision. A false-positive closure is wrong because the scanner identified a real weakness on an unsupported asset; closing it hides exposure rather than addressing it. Removing the finding until replacement is wrong because reporting should reflect current risk, not future remediation timelines, and omitting open risks breaks accountability. Delaying the report or waiting for a quarterly review is wrong because critical or high vulnerabilities require timely communication, especially when remediation is blocked. Exam caveat: choose the answer that documents mitigation and residual risk, not the one that suppresses, delays, or removes the vulnerability. Operational check: in the risk register, record the CVE, patch blocker, compensating controls, control owner, review date, and residual risk rating.