CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A vulnerability management team has two findings to remediate this week: Vulnerability A has a CVSS score of 9.8 but exists only on an isolated internal lab server with no network access. Vulnerability B has a CVSS score of 7.5, is on an internet-facing web server, and has a publicly available exploit actively being used in the wild. Which vulnerability should be prioritized for immediate remediation?
- AVulnerability A, because its CVSS score is higher
- BNeither is urgent since both scores are below 10.0
- CBoth should be remediated simultaneously regardless of context
- DVulnerability B, because it combines internet exposure with active exploitation
Show answer & explanationAnswer & explanation
Correct answer: D. Vulnerability B, because it combines internet exposure with active exploitation
Risk-based prioritization considers exploitability and exposure, not just raw CVSS score. Vulnerability B is internet-facing and has a known exploit in active use, giving it a much higher real-world risk than the isolated, higher-scoring Vulnerability A.
Why the other options are wrong
- A. CVSS alone ignores exposure and real-world exploitation context.
- B. Score thresholds alone don't determine urgency; context does.
- C. Resources are typically limited, requiring true risk-based ordering rather than parallel treatment.
Risk-Based Vulnerability Prioritization
Prioritizing remediation based on exploitability, asset exposure/criticality, and threat intelligence, not just CVSS base score.
- Consider exposure (internet-facing vs isolated)
- Factor in active exploitation (e.g., EPSS, CISA KEV list)
- Asset criticality to business operations matters
Memory trick: Exposed and exploited beats merely scary-scored.