Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security analyst is reviewing a vulnerability scan report that lists multiple vulnerabilities for a single server. To effectively prioritize remediation efforts, the analyst should consider the CVSS score, the asset's criticality, and which other key factor?

  1. AThe operating system of the scanning workstation.
  2. BThe number of other vulnerabilities on the same asset.
  3. CThe ease and likelihood of exploitation.
  4. DThe vendor of the scanning tool used.
Show answer & explanation

Correct answer: C. The ease and likelihood of exploitation.

Effective prioritization of vulnerabilities requires considering not just the base severity (CVSS score) and the importance of the asset, but also the practical 'exploitability' of the vulnerability. A high-severity vulnerability that is difficult to exploit or has no known exploits poses less immediate risk than a medium-severity vulnerability that is easily exploited. The ease and likelihood of exploitation directly influence the 'likelihood' component of overall risk.

Why the other options are wrong

  • A. The operating system of the scanning workstation is irrelevant to vulnerability prioritization.
  • B. While multiple vulnerabilities on an asset are a concern, the *number* itself doesn't directly influence the prioritization of *individual* vulnerabilities as much as their exploitability.
  • D. The vendor of the scanning tool is irrelevant to vulnerability prioritization.

Vulnerability Prioritization Factors

Key elements used to rank vulnerabilities for remediation, often including severity, asset criticality, and exploitability.

  • Helps focus resources on the most impactful risks.
  • Balances technical severity with business context.
  • Dynamic, as threat landscape changes.

Memory trick: Severity, Asset, Exploit: The S.A.F.E. way to prioritize.

More Vulnerability Management questions