Courseiva
easyMultiple ChoiceObjective-mapped

CAS-004 Practice Question: Implementing a risk management framework and…

A company is implementing a risk management framework and needs to prioritize remediation of vulnerabilities based on potential impact. Which of the following is the MOST appropriate approach?

⚠ Common exam trap

CompTIA often tests the misconception that CVSS score alone is sufficient for prioritization, but the exam emphasizes that risk-based decisions must incorporate asset value and financial impact, not just technical severity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a quantitative risk assessment using asset value and loss expectancy

Quantitative risk assessment (QRA) uses asset value (AV) and single loss expectancy (SLE) or annualized loss expectancy (ALE) to compute risk in monetary terms, directly aligning remediation priority with potential business impact. This approach ensures that vulnerabilities affecting high-value assets with significant loss expectancy are addressed first, which is the core principle of risk-based vulnerability management in the CAS-004 Governance, Risk and Compliance domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Focus on vulnerabilities with the highest CVSS score regardless of asset value

    Why it's wrong here

    CVSS score alone does not account for asset criticality.

  • Remediate all vulnerabilities within 30 days of discovery

    Why it's wrong here

    This is a timeline, not a prioritization method.

  • Perform a quantitative risk assessment using asset value and loss expectancy

    Why this is correct

    This approach combines asset value and potential loss to prioritize risks effectively.

  • Address vulnerabilities in order of ease of exploitation

    Why it's wrong here

    Ease of exploitation only addresses likelihood, not full risk.

About these practice questions

This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.