Controls and risk management is the vocabulary of a vulnerability program: what kind of control something is, what job it does, how much risk the organization keeps, and which policies and tests hold the program together (objective 2.4). Its verb is explain, so the items turn on choosing the right term for a described situation.
Exam code CS0-004
Domain weight 26%
Tickets here 16
Terms 2.4 expects you to explainRule
Classify a control twice: by type (administrative, technical, physical) and by function (preventative, detective, responsive, corrective).
Use inherent risk, residual risk and risk appetite correctly.
Choose a risk strategy: accept, transfer, avoid or mitigate.
Explain how policies, governance and service-level objectives (SLOs) run the program.
Place static and dynamic application security testing (SAST, DAST) and OWASP SAMM in application security, and software composition analysis (SCA) and the software bill of materials (SBOM) in third-party risk.
01Type and function are two questions
scroll →
One example per cell. A stem can ask for either axis, so name both.
02Reading the two axes
Types say what a control is made of. The CS0-004 objectives (version 2.0) use administrative, technical and physical, while the CS0-003 objectives said managerial, operational and technical (both checked October 2026). Older practice material may also call technical controls "logical". Translate those words into the CS0-004 terms when you read a stem.
Functions describe timing. A preventative control stops the event, a detective control notices it, a responsive control acts while it is underway, and a corrective control repairs the damage afterward. Responsive and corrective are the pair most often swapped. If the action happens during the event it is responsive; if it restores something after, corrective.
One device can sit in two cells. A camera that records is detective. Put a guard behind the camera with orders to intervene and the same setup becomes part of a responsive control. Classify by what the control does in the scenario.
03Risk terms that sound alike
Inherent risk
The risk before any control is applied: the raw exposure of an asset with a weakness.
Residual risk
What remains after controls. It is never zero; the question is whether it fits the appetite.
Risk appetite
How much risk leadership is willing to carry in pursuit of the organization's goals. Residual risk is judged against it.
04Four risk strategies
Strategy → what it does → the sign in a stemscroll →
Strategy
What it does
Sign in the stem
Accept
Keeps the risk, documented and approved
Residual risk within appetite, or the fix costs more than the loss
Transfer
Moves the financial impact to another party
Insurance or a contract clause; accountability stays home
Avoid
Stops the activity that creates the risk
Retire the service, drop the feature, leave the market
05Policy, application security and the supply chain
Policies, governance and SLOs
The vulnerability management policy sets ownership and timelines, and governance checks that the policy is followed. A service-level objective is an internal target the security team commits to. A service-level agreement (SLA) is a contractual promise, to a customer or from a vendor. Reporting measures the program against both, the subject of vulnerability reporting and communication.
Application security
SAST reads source code without running it. DAST tests the running application from outside. OWASP SAMM, the Software Assurance Maturity Model, is not a test at all. It is a model for measuring how mature an organization's secure-software practice is, so a stem about assessing a development program's maturity points to SAMM. The testing trio is compared in SAST vs DAST vs SCA.
Third-party risk
Supply-chain risk is the risk you inherit through vendors and components you did not write. SCA inventories the third-party libraries in a build and matches them to known vulnerabilities. The SBOM is the resulting ingredient list, which CISA promotes as a standard artifact. When a flaw lands in a popular library, an organization that keeps SBOMs can answer "are we affected?" with a search.
Name the type, then the function. The right term on the wrong axis is still a wrong answer.
06Vocabulary under pressure
Name the axis first, type or function, and only then the term. The stems describe a control, a policy or a decision and ask what to call it.
Ticket 1 / 16
0 right
INC-001
Which of the following can be considered a corrective action after detecting malware on a company workstation?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AInstalling antivirus is a preventive control aimed at stopping future infections, not at fixing the system already infected.
BPhishing awareness training is a preventive administrative control; it does not repair the infected workstation.
CCorrect: Restoring the workstation from a known-clean backup fixes the damage after the fact, which is what a corrective control does.
DIsolating the workstation is containment; it stops the spread but does not return the system to a good state.
INC-002
Which of the following is considered a preventive physical security control?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
ASecurity cameras are mainly detective (they record and help identify events) and somewhat deterrent, but they do not physically stop entry.
BCorrect: A fence physically blocks unauthorized access before it happens, which makes it a preventive physical control.
CSecurity training is an administrative control, not a physical one.
DFire extinguishers limit damage after a fire starts, so they are corrective or compensating physical controls and do nothing preventive.
INC-003
An Incident Response Team has deployed a new firewall to protect the organization's network. Which type of control is the firewall considered in this context?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
AAdministrative controls are policies, procedures and training, so hardware and software devices fall outside them.
BPhysical controls are things like locks, fences and guards that restrict physical access, and they do nothing to network traffic.
CThis names a control's function (fixing things after an event), but the question asks for its type, and a firewall mostly prevents.
DCorrect: A firewall is a technical control, hardware or software that enforces access rules on traffic; older material calls the same category logical.
INC-004
Which of the following is an example of a corrective security control?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
APassword policies stop weak passwords before they are exploited, so they are preventive.
BSecurity training reduces future mistakes, so it is a preventive administrative control.
CCorrect: Patching fixes a vulnerability that has already been found, which is the role of a corrective control.
DA firewall blocks unwanted traffic before it reaches systems, so it is a preventive technical control.
INC-005
Which of the following elements should be included in a vulnerability management policy to ensure proper governance?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ADetailed patching steps for each system belong in procedures or runbooks instead of the governing policy.
BNaming specific tools makes a policy go out of date whenever tools change; tool choice belongs in standards or procedures.
CCorrect: A governance policy defines who is responsible, how fast fixes must happen, how exceptions are approved, and how the program is measured.
DA list of CVEs is operational data that changes daily, which is why it has no place in policy content.
INC-006
During an internal audit, the security team discovers persistent remediation SLA breaches across multiple critical business units. What governance failure most likely caused this systemic issue?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AAutomated patching for non-critical workstations would not cause repeated SLA breaches across critical business units.
BHaving QA test critical patches is a normal practice and no sign of a governance failure.
CCorrect: Repeated SLA breaches across many units mean no one is tracking remediation SLAs or checking that compensating controls work, which is a governance failure.
DPatching outside maintenance windows is a change-management problem, and it would speed fixes rather than cause SLA breaches.
INC-007
Which of the following practices most directly leads to unchecked risk accumulation and compromised zero-trust architectures over time?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
APrioritizing by raw CVSS without context is poor practice, but it misorders work rather than letting suppressed findings pile up unseen.
BUntested rollbacks create change risk, which is different from a gradual buildup of unreviewed risk.
CCorrect: Suppressions and exceptions that are never reviewed keep hiding vulnerabilities after their justification has expired, so unmanaged risk quietly grows.
DUnauthenticated external scans miss internal details and produce gaps, but they do not suppress known findings over time.
INC-008
Which of the following is a key component of creating an effective vulnerability remediation strategy?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: Severity-based SLAs set clear deadlines, so critical issues are fixed fast and lower-risk ones get reasonable timeframes.
BFixing CVEs in alphabetical or numeric order ignores risk completely.
CPublic exploit availability is one input to prioritization, but ignoring everything else leaves serious risks unaddressed.
DFixing everything at once regardless of impact is not realistic and ignores business disruption and prioritization.
INC-009
During a post-incident review, analysts discover an internet-facing server was compromised using an old vulnerability. Interim network mitigations were installed but proved ineffective. Which primary governance failure led to this?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ALog analysis helps design mitigations, but the failure here is that no one checked whether the mitigations worked or tracked the real fix.
BExecutive summaries are meant to leave out technical configuration details, so omitting them is not a failure.
CCorrect: Interim controls were never checked for effectiveness and the old vulnerability was never fixed on schedule, which is a failure to track remediation SLAs.
DRaw scanner counts in leadership reports would not have protected the server.
INC-010
A cybersecurity team is initiating steps to identify vulnerabilities, potential threats, and methods for improving system defenses. Which phase of the risk management framework does this activity fall under?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: Identifying vulnerabilities, threats, and possible impacts is risk assessment, the step that comes before deciding how to treat the risk.
BRisk mitigation comes after assessment, once you choose and apply responses to risks already identified.
CRisk monitoring is the ongoing tracking of risks and control effectiveness after controls are in place.
DControl implementation is putting chosen controls in place, which follows assessment and treatment decisions.
INC-011
A corporation has experienced several phishing attacks over the last few months. An analysis revealed that employees had been clicking on malicious links and providing sensitive information. To mitigate this, which policy would be the most effective to implement?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AA data retention policy sets how long data is kept and does nothing to stop staff from clicking phishing links.
BAn acceptable use policy defines allowed use of company resources, but it does not teach employees to recognize phishing.
CCorrect: the root cause is people falling for phishing, so a security awareness training policy, an administrative control that teaches staff to spot and report suspicious messages, addresses it directly.
DAn incident response policy governs what happens after an attack succeeds; it does not lower how often employees fall for phishing.
INC-012
Which of the following is a key challenge when integrating vulnerability management with the software development lifecycle?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ADevelopers do not need to learn network scanning; SDLC integration relies on code and dependency testing such as SAST, DAST, and SCA.
BLicensing costs are a budgeting issue and only a side concern when integrating security into development.
CCorrect: Security checks in the pipeline have to catch real issues without slowing releases so much that teams try to bypass them.
DLanguage choice is an engineering decision; security tools must support what the team uses, but that is not the main integration challenge.
INC-013
Which CI/CD gating policy best balances security with developer velocity across environments?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: Blocking critical CVEs from production while allowing documented exceptions in lower environments protects what is exposed without stalling development.
BBlocking every pipeline on any CVE stops delivery constantly, including for low-risk or unreachable findings.
CDisabling all gates removes security checks completely, which trades away safety for speed.
DIdentical rules everywhere ignore that dev and staging carry different risk from production and create needless friction.
INC-014
Which governance best practice optimally shifts an organization from point-in-time scanning to continuous supply chain intelligence?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AManual reviews of direct dependencies at major releases are still point-in-time and miss transitive dependencies.
BAuthenticated filesystem scans go deeper, but they are still periodic scans and give no continuous supply chain intelligence.
CCorrect: Feeding SBOMs into the vulnerability workflow lets newly disclosed CVEs be matched automatically against known components at any time, not just during scans.
DAnnual vendor questionnaires are slow, self-reported, and say nothing about new vulnerabilities between reviews.
INC-015
Based on the SBOM intelligence provided below, which service requires immediate prioritization of specific layer-7 protections to mitigate its declared weakness?
Exhibitscroll →
Internal Service
Declared CWE
Patch Status
Internet Facing
API Node
CWE-89 (SQLi)
Pending
Yes
Human Resources App
CWE-79 (XSS)
Applied
No
Metrics Database
CWE-119 (Buffer Overflow)
Pending
No
Forward Proxy Server
CWE-400 (Resource Exhaustion)
Applied
Yes
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
AThe forward proxy is internet-facing, but its resource-exhaustion weakness is already patched.
BCorrect: API Node is internet-facing with an unpatched SQL injection weakness (CWE-89), exactly the kind of flaw layer-7 controls such as WAF rules can filter while the patch is pending.
CThe metrics database has a pending patch, but it is not internet-facing, and a buffer overflow is not something layer-7 web filtering reliably stops.
DThe HR app's XSS weakness is already patched and the app is not exposed to the internet.
INC-016
A cybersecurity analyst is examining the lifecycle of managing vulnerabilities. The analyst has just completed the identification and analysis phase. What is the next phase in vulnerability management?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
AAssessment is essentially the analysis work the stem says is already finished, so repeating it is not the next phase.
BCorrect: Once vulnerabilities are identified and analyzed, the next phase is remediation, meaning patching, reconfiguring, or applying compensating controls.
CIdentification is the phase that was just completed, so it cannot come next.
DReporting follows remediation and verification, when there are results to report.
Shift tally
0 / 0
07Controls and risk, asked often
Will the control-type names I learned for CS0-003 still work?
Not word for word. The CS0-003 objectives grouped controls as managerial, operational and technical. The CS0-004 objectives, version 2.0 use administrative, technical and physical. The four functions (preventative, detective, responsive, corrective) appear in both (CompTIA objectives, checked October 2026).
If we buy cyber insurance, is that mitigation or transfer?
Transfer. It moves the financial impact to the insurer. It does not make the event less likely, and the organization keeps both the risk ownership and the duty to respond.
Who sets my organization's risk appetite?
Leadership: the board or senior management. The security team measures residual risk against that line and reports the findings that sit above it, which is where accept-or-mitigate decisions get escalated.
Keep the queue going on your phone
Our practice app carries CySA+ questions to your phone, on iPhone and Android.