CS0-003 Vulnerability Management Practice Question
A company uses a patch management tool to track compliance across its server fleet. The security team needs to prioritize vulnerabilities for patching. Which THREE factors should be considered when prioritizing?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EPSS probability score
CVSS score indicates severity, EPSS estimates exploitation likelihood, and asset criticality reflects business impact. Patch availability is more about remediation capability than prioritization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EPSS probability score
Why this is correct
The EPSS probability score is a data-driven metric from FIRST that estimates the likelihood a vulnerability will be exploited in the wild within 30 days. It is derived from real-world exploit data, CVE attributes, and threat intelligence, making it a strong indicator of active exploitation risk. As a correct prioritization input, it helps security teams focus on vulnerabilities that are most likely to be attacked, rather than just those with high theoretical severity. This is a valid and important factor for risk-based prioritization.
- ✓
Asset criticality and exposure
Why this is correct
Asset criticality and exposure directly influence the real-world impact of a vulnerability. A flaw affecting a public-facing financial application or a system holding sensitive data presents a far greater business risk than the same vulnerability on an internal, low-value asset. This context is essential for prioritization because it converts raw vulnerability data into organizational risk. A patch manager that ignores this will likely waste resources fixing low-risk issues while leaving high-impact assets vulnerable.
- ✗
Availability of a patch from the vendor
Why it's wrong here
Patch availability is a matter of remediation timing, not prioritization. The existence of a vendor patch does not alter the underlying severity or exploitability of a vulnerability; it simply means you have an option to remediate it. In risk-based prioritization you first decide which vulnerabilities need attention based on likelihood and impact, then schedule the fix. Therefore, patch availability alone is not a valid prioritization criterion, although it can influence the urgency of deploying an existing fix.
- ✓
CVSS base score
Why this is correct
The CVSS base score provides a standardized, vendor-neutral rating (0-10) of a vulnerability's intrinsic severity, based on attack vector, complexity, privileges required, user interaction, and impact on confidentiality, integrity, and availability. It is a widely used starting point for prioritization because it reflects the technical severity that does not depend on any specific environment. However, it does not account for exploitation likelihood or business context, so while it is a correct prioritization factor, it should be combined with other inputs. This score is an objective and repeatable metric suitable for initial triage.
- ✗
Number of plugins that detected the vulnerability
Why it's wrong here
The number of plugins that detected a vulnerability is not a valid prioritization metric, as it is an artifact of scanning tool coverage, not the actual risk. Multiple plugins may flag the same CVE due to overlapping detection rules or false positives, without adding any new information about exploitation likelihood or business impact. Relying on plugin count could cause analysts to chase ambiguous alerts while ignoring genuinely severe issues that only one scanner identified. Consequently, this metric has no bearing on which vulnerabilities should be remediated first.
Go deeper
Related to this question
Learn chapter
Vulnerability Prioritization
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.