A vulnerability assessment identifies a critical CVE with CVSS 9.8 on a web server. The finding notes the vulnerability is not exploitable because a compensating firewall rule blocks access to the affected service. How should the vulnerability management team handle this?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because compensating controls reduce risk but do not eliminate the underlying vulnerability. Firewall rules can be misconfigured, bypassed, or accidentally removed.
Full explanation below image
Full Explanation
C is correct because compensating controls reduce risk but do not eliminate the underlying vulnerability. Firewall rules can be misconfigured, bypassed, or accidentally removed. Patching remains the permanent fix and the compensating control requires ongoing monitoring. A is wrong because closing the finding creates false assurance; the vulnerability remains. B is wrong because CVSS base scores reflect inherent vulnerability severity, not mitigated risk; environmental scores are separate. D is wrong because rescanning confirms the finding's existence, not the effectiveness of the compensating control.