Repair contextual vulnerability response decisions

A hands-on CS0-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CS0-004 practice

Certification
CS0-004
Format
Structured configuration
Difficulty
hard
Estimated time
35 min
Automated checks
8

The brief

Repair remediation-rules.json with hitPolicy unique or first and 1..24 distinct {id,when,then} rules. Inputs: applicability is confirmed, unknown or not-applicable; exploitation known or not-known; exposure external, internal or isolated; impact critical or standard. when category arrays combine by AND; omitted inputs are wildcards. then must contain urgency (none,verify,emergency,planned), hours (integer 0,4,24,168) and control (none,preserve-evidence,restrict-exposure,monitor). Local policy: not-applicable always yields none/0/none. Unknown applicability yields verify/4/preserve-evidence when exploitation is known, otherwise verify/24/none; uncertainty cannot become closure or confirmed applicability. For confirmed applicability and known exploitation, external/internal assets yield emergency/4/restrict-exposure and isolated assets emergency/24/preserve-evidence. Isolation changes the route, not the applicability fact. For confirmed applicability without known exploitation, critical external assets yield planned/24/restrict-exposure; every remaining combination yields planned/168/monitor. Evaluate all 36 combinations; exact output triples and all three outputs matter. Unique requires exactly one hit. First intentionally permits overlap when specific rows precede their fallback. Every input needs a result and every row must contribute; a shadowed fallback is a defect. Use only supplied fields and correctly typed values. Rule IDs carry no risk or approval meaning. Distinct disjoint and priority representations are valid. Run tests, inspect actual mismatches, then repair exposure or uncertainty consequences without Reset.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • An explicit hit policy and distinct editable rule identities remain well formed.
  • The supplied assessment inputs and typed complete consequences remain intact.
  • Every supplied finding context has a conditional response disposition.
  • Conditional priorities resolve each context under the selected hit policy.
  • Every rule can actually contribute a response decision.
  • Actual applicability and exploitation evidence determines urgency without inventing closure.
  • The authored response deadline follows evidence confidence and actual exposure context.
  • Temporary control or preservation follows the actual decision context.

Where this sits in the CS0-004 blueprint

Domain
Vulnerability Management
Objective
Vulnerability Prioritization and Mitigation
Skill
Exploitation, Context and Verification

Part of CS0-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.