CompTIA Security+ (SY0-701)Security OperationsHard

A vulnerability management program identified two findings: Finding X has a CVSS base score of 7.5 affecting an internal test server with no known exploit, and Finding Y has a CVSS base score of 6.8 affecting an internet-facing payment server with a public exploit available. Which finding should be remediated first?

  1. AFinding X, because internal servers are always higher priority
  2. BFinding X, because its base CVSS score is higher
  3. CBoth should be remediated simultaneously with no prioritization
  4. DFinding Y, because exploitability and asset exposure increase real-world risk
Show answer & explanation

Correct answer: D. Finding Y, because exploitability and asset exposure increase real-world risk

Effective risk prioritization considers more than the base CVSS score; it factors in exploit availability and asset criticality/exposure. Finding Y, despite a lower base score, poses greater real-world risk because it is internet-facing, processes payments, and has a known public exploit, making it the higher priority for remediation.

Why the other options are wrong

  • A. Internal servers are not inherently higher priority than exposed, exploitable systems.
  • B. Relying solely on base score ignores exploitability and business context, which drive actual risk.
  • C. Simultaneous remediation ignores resource constraints and risk-based prioritization principles.

Risk-Based Vulnerability Prioritization

An approach to remediation that considers CVSS score alongside exploit availability, asset criticality, and exposure rather than score alone.

  • A lower CVSS score with active exploitation can be higher risk
  • Asset exposure (internet-facing) increases real-world risk
  • Frameworks like EPSS incorporate exploit likelihood into prioritization

Memory trick: Score alone doesn't tell the whole story—context is king.

More Security Operations questions