CompTIA Security+ (SY0-701)Security OperationsHard
A vulnerability management program identified two findings: Finding X has a CVSS base score of 7.5 affecting an internal test server with no known exploit, and Finding Y has a CVSS base score of 6.8 affecting an internet-facing payment server with a public exploit available. Which finding should be remediated first?
- AFinding X, because internal servers are always higher priority
- BFinding X, because its base CVSS score is higher
- CBoth should be remediated simultaneously with no prioritization
- DFinding Y, because exploitability and asset exposure increase real-world risk
Show answer & explanationAnswer & explanation
Correct answer: D. Finding Y, because exploitability and asset exposure increase real-world risk
Effective risk prioritization considers more than the base CVSS score; it factors in exploit availability and asset criticality/exposure. Finding Y, despite a lower base score, poses greater real-world risk because it is internet-facing, processes payments, and has a known public exploit, making it the higher priority for remediation.
Why the other options are wrong
- A. Internal servers are not inherently higher priority than exposed, exploitable systems.
- B. Relying solely on base score ignores exploitability and business context, which drive actual risk.
- C. Simultaneous remediation ignores resource constraints and risk-based prioritization principles.
Risk-Based Vulnerability Prioritization
An approach to remediation that considers CVSS score alongside exploit availability, asset criticality, and exposure rather than score alone.
- A lower CVSS score with active exploitation can be higher risk
- Asset exposure (internet-facing) increases real-world risk
- Frameworks like EPSS incorporate exploit likelihood into prioritization
Memory trick: Score alone doesn't tell the whole story—context is king.