Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementHard
A cybersecurity team has just completed a vulnerability scan of their production environment and generated a report with hundreds of findings. Before proceeding with remediation, they need to determine which vulnerabilities pose the most significant risk to the organization. Which of the following factors is LEAST important when prioritizing these vulnerabilities?
- AAge of the vulnerability (how long it has been known).
- BBusiness impact of the affected asset.
- CAvailability of a security patch or workaround.
- DExploitability of the vulnerability.
Show answer & explanationAnswer & explanation
Correct answer: A. Age of the vulnerability (how long it has been known).
While the age of a vulnerability might correlate with exploit maturity, it's not a direct measure of current risk. Factors like exploitability, business impact, and the ease of remediation (patch availability) are far more critical for immediate prioritization. A very old, but unexploitable vulnerability on a non-critical asset is less urgent than a new, highly exploitable one on a critical system.
Why the other options are wrong
- B. The business impact of the affected asset directly determines potential damage, making it highly important.
- C. Knowing if a patch or workaround exists directly impacts the feasibility and timeline of remediation, making it a key prioritization factor.
- D. Exploitability is a critical factor; easily exploitable vulnerabilities are higher priority.
Vulnerability Prioritization Factors
Key elements considered when ranking vulnerabilities to determine which should be addressed first based on risk.
- Exploitability: How easily can the vulnerability be exploited?
- Impact: What is the potential damage if exploited?
- Asset Criticality: How important is the affected system to the business?
- Remediation Availability: Is a patch or workaround readily available?
Memory trick: Impact, Exploit, Asset, Patch: Prioritize with these four.