CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A vulnerability management team has two findings to remediate this week: Vulnerability A has a CVSS score of 9.8 but exists only on an isolated internal lab server with no network access. Vulnerability B has a CVSS score of 7.5, is on an internet-facing web server, and has a publicly available exploit actively being used in the wild. Which vulnerability should be prioritized for immediate remediation?

  1. AVulnerability A, because its CVSS score is higher
  2. BNeither is urgent since both scores are below 10.0
  3. CBoth should be remediated simultaneously regardless of context
  4. DVulnerability B, because it combines internet exposure with active exploitation
Show answer & explanation

Correct answer: D. Vulnerability B, because it combines internet exposure with active exploitation

Risk-based prioritization considers exploitability and exposure, not just raw CVSS score. Vulnerability B is internet-facing and has a known exploit in active use, giving it a much higher real-world risk than the isolated, higher-scoring Vulnerability A.

Why the other options are wrong

  • A. CVSS alone ignores exposure and real-world exploitation context.
  • B. Score thresholds alone don't determine urgency; context does.
  • C. Resources are typically limited, requiring true risk-based ordering rather than parallel treatment.

Risk-Based Vulnerability Prioritization

Prioritizing remediation based on exploitability, asset exposure/criticality, and threat intelligence, not just CVSS base score.

  • Consider exposure (internet-facing vs isolated)
  • Factor in active exploitation (e.g., EPSS, CISA KEV list)
  • Asset criticality to business operations matters

Memory trick: Exposed and exploited beats merely scary-scored.

More Vulnerability Management questions