CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A vulnerability management program cross-references CVSS with the Exploit Prediction Scoring System (EPSS). Vulnerability X has a CVSS base score of 7.5 and an EPSS score of 0.02 (2% probability of exploitation in the next 30 days). Vulnerability Y has a CVSS base score of 6.1 and an EPSS score of 0.89 (89% probability). With limited patching resources this week, which vulnerability should be prioritized first?

  1. AVulnerability Y, because its EPSS score indicates a much higher near-term probability of real-world exploitation
  2. BVulnerability X, because CVSS severity always outweighs likelihood of exploitation
  3. CVulnerability X, because a low EPSS score means it has already been patched by the vendor
  4. DNeither should be prioritized because both CVSS scores are below 9.0
Show answer & explanation

Correct answer: A. Vulnerability Y, because its EPSS score indicates a much higher near-term probability of real-world exploitation

EPSS estimates the probability that a vulnerability will be exploited in the wild within a given time window, complementing CVSS severity with real-world exploitation likelihood. Vulnerability Y's 89% EPSS score signals it is far more likely to be actively exploited soon, so risk-based prioritization favors patching it first even though its CVSS score is lower.

Why the other options are wrong

  • B. Severity alone ignores exploitation likelihood, which is a key risk factor.
  • C. A low EPSS score reflects low predicted exploitation probability, not patch status.
  • D. A CVSS threshold of 9.0 is not a universal rule and ignores exploitation likelihood entirely.

EPSS (Exploit Prediction Scoring System)

A data-driven scoring system that estimates the probability (0-1) that a vulnerability will be exploited in the wild within the next 30 days, used to complement CVSS in risk-based prioritization.

  • Produces a probability score, unlike CVSS's severity score
  • Updated regularly using real-world threat intelligence and exploit data
  • High EPSS + moderate CVSS can outrank low EPSS + high CVSS for remediation priority

Memory trick: CVSS says how bad, EPSS says how likely — likely wins the race this week.

More Vulnerability Management questions