CAS-004 Security Operations Practice Question
A vulnerability management team is prioritizing patches for a set of critical vulnerabilities. Vulnerability A has a CVSS base score of 9.8, vulnerability B has a CVSS base score of 7.5, and vulnerability C has a CVSS base score of 8.2. However, vulnerability B is actively being exploited in the wild, while the others are not. Which vulnerability should be patched first according to best practices?
⚠ Common exam trap
The trap is focusing solely on CVSS scores and ignoring the critical factor of active exploitation, which should override base score in prioritization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerability B because it is actively exploited
Vulnerability B should be patched first because it is actively being exploited in the wild. While CVSS base scores indicate severity, active exploitation means the vulnerability poses an immediate and real threat. Best practices prioritize vulnerabilities with known exploits, especially those used in active attacks, over higher-scored but unexploited ones.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All three should be patched simultaneously
Why it's wrong here
Patching all three at once ignores prioritisation entirely, delaying the actively exploited vulnerability behind two unexploited ones. Simultaneous remediation is tempting when resources are ample and change windows are scarce, but best practise ranks known exploitation above base score alone.
- ✓
Vulnerability B because it is actively exploited
Why this is correct
CVSS base scores measure intrinsic severity only, not real-world threat. Exploit availability and active exploitation are captured by temporal and threat metrics, which raise actual risk. Since B is being exploited in the wild, it poses immediate likelihood of compromise, so best practise prioritises it over higher-scoring but unexploited flaws.
- ✗
Vulnerability C because it has a higher base score than B
Why it's wrong here
C's higher base score does not outweigh B's confirmed exploitation in the wild, so this ordering still leaves the actively attacked vulnerability unpatched. It tempts because comparing base scores is objective and simple, but exploitation status, not severity ranking, drives urgency here.
- ✗
Vulnerability A because it has the highest base score
Why it's wrong here
CVSS base score measures intrinsic severity, not exploitation likelihood, so patching A first leaves the actively exploited vulnerability B exposed. It tempts because base score is the most visible metric, and it would be the correct tiebreaker only when no vulnerability is known to be exploited.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.