CompTIA Security+ (SY0-701)Security OperationsMedium
A vulnerability scan reports a finding with a CVSS v3.1 base score of 9.8. Based on this score, how should the security team prioritize remediation?
- ATreat it as low priority since scores above 9.0 indicate false positives
- BSchedule remediation during the next annual patch cycle
- CTreat it as critical severity and remediate as soon as possible
- DIgnore it because CVSS scores only apply to network devices
Show answer & explanationAnswer & explanation
Correct answer: C. Treat it as critical severity and remediate as soon as possible
CVSS v3.1 base scores range from 0.0 to 10.0, with 9.0–10.0 classified as Critical severity. A score of 9.8 indicates a severe vulnerability that is likely easy to exploit with significant impact, requiring urgent remediation rather than delay.
Why the other options are wrong
- A. High scores indicate genuine severity, not false positives.
- B. Waiting a full year for a critical vulnerability leaves the organization exposed.
- D. CVSS applies broadly to software, hardware, and network vulnerabilities.
CVSS Scoring
Common Vulnerability Scoring System rates vulnerability severity from 0.0 to 10.0, guiding remediation prioritization.
- 0.1-3.9 = Low
- 4.0-6.9 = Medium
- 7.0-8.9 = High
- 9.0-10.0 = Critical
Memory trick: Nine and up, fix it right now.