CompTIA CySA+ (CS0-003)Vulnerability ManagementHard
A vulnerability management team must choose which finding to remediate first this week. Vulnerability A has a CVSS Base Score of 7.5, appears on the CISA Known Exploited Vulnerabilities (KEV) catalog, and affects an internet-facing VPN appliance. Vulnerability B has a CVSS Base Score of 9.1 but affects an internal file server with no known exploitation activity. Which vulnerability should be prioritized first, and why?
- ABoth should be scheduled with equal priority since their CVSS scores are within two points of each other
- BVulnerability B, because a higher CVSS score always takes precedence regardless of other factors
- CVulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score
- DVulnerability B, because internal systems must always be patched before external systems
Show answer & explanationAnswer & explanation
Correct answer: C. Vulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score
Risk-based prioritization considers exploitability in the wild (KEV listing) and exposure (internet-facing) alongside CVSS severity; a lower-scored but actively exploited, externally reachable vulnerability typically represents greater real-world risk than a higher-scored but unexploited internal one.
Why the other options are wrong
- A. Treating them as equal priority ignores the significant risk difference introduced by active exploitation and exposure.
- B. Relying solely on CVSS ignores real-world exploitation and exposure context, which the KEV catalog captures.
- D. There is no rule that internal systems always take precedence over external ones.
Risk-Based Prioritization (KEV Catalog)
Remediation prioritization approach that factors in real-world exploitation evidence (e.g., CISA KEV catalog) and asset exposure, not just CVSS severity.
- CISA KEV lists vulnerabilities confirmed to be exploited in the wild
- Internet-facing assets carry higher exposure risk than internal-only assets
- Combines exploitability, exposure, and asset value with CVSS for prioritization
Memory trick: CVSS tells severity; KEV tells reality.