Controls, Risk Handling and Remediation
This topic covers vulnerability controls, patching, maintenance windows, exceptions, attack surface management, governance, compliance, and risk handling.
How to study for CompTIA CySA+
Treat each CySA+ item as an analyst decision: identify telemetry, scope risk, validate findings, contain impact, communicate clearly, and improve controls.
Core concepts
Concept 1
Mitigation should match vulnerability type, exploit path, business context, compensating controls, and change window.
Exam cue: Choose mitigation based on vulnerability type and exploit path.
Concept 2
Preventive, detective, corrective, and compensating controls serve different purposes in vulnerability management.
Exam cue: Match the control type to the intended risk outcome.
Concept 3
Risk handling should be documented, time-bound, owned, and aligned to policy.
Exam cue: Document exceptions, ownership, and review dates.
Risk pitfalls and guardrails
Accepting risk indefinitely without approval or review.
Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.
Patching without testing when service impact is material.
Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.
Treating a compensating control as if it removes the underlying vulnerability.
Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.
Memory anchors
Compensating Control
A compensating control reduces risk when the ideal control is not feasible.
Patch Management
Patch management tests, schedules, deploys, verifies, and documents updates.
Maintenance Window
A maintenance window coordinates change timing, staffing, rollback, and communication.
Exception
An exception documents approved deviation from policy with scope, owner, and expiration.
Attack Surface
Attack surface includes exposed systems, services, identities, data, and interfaces.
Preventive Control
A preventive control reduces the likelihood that a vulnerability can be exploited.
Detective Control
A detective control identifies exploitation or control failure so responders can act.
Risk Transfer
Risk transfer shifts specified financial or operational consequences to another party while residual risk remains.
Risk Acceptance
Risk acceptance acknowledges a risk under approved authority and documented conditions.
Remediation Tracking
Remediation tracking follows findings through assignment, action, validation, and closure.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
Summit Freight cannot eliminate a legacy protocol on legacy application this quarter. Network policy can restrict it to two managed jump hosts. Which recommendation is MOST appropriate? No response action has been taken yet.
Pine County receives an emergency patch for a remotely exploited flaw on public customer-portal, but the update may break a critical plugin. What should the analyst do FIRST? No response action has been taken yet.
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
