Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A vulnerability management team is prioritizing patches for a set of critical vulnerabilities. Vulnerability A has a CVSS base score of 9.8, vulnerability B has a CVSS base score of 7.5, and vulnerability C has a CVSS base score of 8.2. However, vulnerability B is actively being exploited in the wild, while the others are not. Which vulnerability should be patched first according to best practices?

⚠ Common exam trap

The trap is focusing solely on CVSS scores and ignoring the critical factor of active exploitation, which should override base score in prioritization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability B because it is actively exploited

Vulnerability B should be patched first because it is actively being exploited in the wild. While CVSS base scores indicate severity, active exploitation means the vulnerability poses an immediate and real threat. Best practices prioritize vulnerabilities with known exploits, especially those used in active attacks, over higher-scored but unexploited ones.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All three should be patched simultaneously

    Why it's wrong here

    Patching all three at once ignores prioritisation entirely, delaying the actively exploited vulnerability behind two unexploited ones. Simultaneous remediation is tempting when resources are ample and change windows are scarce, but best practise ranks known exploitation above base score alone.

  • ✓

    Vulnerability B because it is actively exploited

    Why this is correct

    CVSS base scores measure intrinsic severity only, not real-world threat. Exploit availability and active exploitation are captured by temporal and threat metrics, which raise actual risk. Since B is being exploited in the wild, it poses immediate likelihood of compromise, so best practise prioritises it over higher-scoring but unexploited flaws.

  • ✗

    Vulnerability C because it has a higher base score than B

    Why it's wrong here

    C's higher base score does not outweigh B's confirmed exploitation in the wild, so this ordering still leaves the actively attacked vulnerability unpatched. It tempts because comparing base scores is objective and simple, but exploitation status, not severity ranking, drives urgency here.

  • ✗

    Vulnerability A because it has the highest base score

    Why it's wrong here

    CVSS base score measures intrinsic severity, not exploitation likelihood, so patching A first leaves the actively exploited vulnerability B exposed. It tempts because base score is the most visible metric, and it would be the correct tiebreaker only when no vulnerability is known to be exploited.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.