CompTIA Security+ (SY0-701)Security OperationsMedium

A vulnerability scan reports a finding with a CVSS v3.1 base score of 9.8. Based on this score, how should the security team prioritize remediation?

  1. ATreat it as low priority since scores above 9.0 indicate false positives
  2. BSchedule remediation during the next annual patch cycle
  3. CTreat it as critical severity and remediate as soon as possible
  4. DIgnore it because CVSS scores only apply to network devices
Show answer & explanation

Correct answer: C. Treat it as critical severity and remediate as soon as possible

CVSS v3.1 base scores range from 0.0 to 10.0, with 9.0–10.0 classified as Critical severity. A score of 9.8 indicates a severe vulnerability that is likely easy to exploit with significant impact, requiring urgent remediation rather than delay.

Why the other options are wrong

  • A. High scores indicate genuine severity, not false positives.
  • B. Waiting a full year for a critical vulnerability leaves the organization exposed.
  • D. CVSS applies broadly to software, hardware, and network vulnerabilities.

CVSS Scoring

Common Vulnerability Scoring System rates vulnerability severity from 0.0 to 10.0, guiding remediation prioritization.

  • 0.1-3.9 = Low
  • 4.0-6.9 = Medium
  • 7.0-8.9 = High
  • 9.0-10.0 = Critical

Memory trick: Nine and up, fix it right now.

More Security Operations questions