CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

A vulnerability management team must choose which finding to remediate first this week. Vulnerability A has a CVSS Base Score of 7.5, appears on the CISA Known Exploited Vulnerabilities (KEV) catalog, and affects an internet-facing VPN appliance. Vulnerability B has a CVSS Base Score of 9.1 but affects an internal file server with no known exploitation activity. Which vulnerability should be prioritized first, and why?

  1. ABoth should be scheduled with equal priority since their CVSS scores are within two points of each other
  2. BVulnerability B, because a higher CVSS score always takes precedence regardless of other factors
  3. CVulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score
  4. DVulnerability B, because internal systems must always be patched before external systems
Show answer & explanation

Correct answer: C. Vulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score

Risk-based prioritization considers exploitability in the wild (KEV listing) and exposure (internet-facing) alongside CVSS severity; a lower-scored but actively exploited, externally reachable vulnerability typically represents greater real-world risk than a higher-scored but unexploited internal one.

Why the other options are wrong

  • A. Treating them as equal priority ignores the significant risk difference introduced by active exploitation and exposure.
  • B. Relying solely on CVSS ignores real-world exploitation and exposure context, which the KEV catalog captures.
  • D. There is no rule that internal systems always take precedence over external ones.

Risk-Based Prioritization (KEV Catalog)

Remediation prioritization approach that factors in real-world exploitation evidence (e.g., CISA KEV catalog) and asset exposure, not just CVSS severity.

  • CISA KEV lists vulnerabilities confirmed to be exploited in the wild
  • Internet-facing assets carry higher exposure risk than internal-only assets
  • Combines exploitability, exposure, and asset value with CVSS for prioritization

Memory trick: CVSS tells severity; KEV tells reality.

More Vulnerability Management questions