CS0-003 Vulnerability Management Practice Question
A company uses a patch management tool to track compliance across its server fleet. The security team needs to prioritize vulnerabilities for patching. Which THREE factors should be considered when prioritizing?
⚠ Common exam trap
CS0-004 often tests the confusion between CVSS (severity) and EPSS (exploit likelihood), or mistakenly treating patch availability as a prioritization factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EPSS probability score
Option A (EPSS probability score) is correct because the Exploit Prediction Scoring System estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, giving a forward-looking, threat-based signal that helps rank which CVEs to patch first. Option B (Asset criticality and exposure) is correct because the same vulnerability poses very different risk depending on whether the affected server is internet-facing, holds sensitive data, or supports a critical business function, so business context must weight the technical severity. Option D (CVSS base score) is correct because it provides a standardized, vendor-neutral measure of the intrinsic severity of a vulnerability (attack vector, complexity, privileges, impact), forming the baseline technical input for prioritization. Option C (availability of a patch from the vendor) is not a prioritization factor per se — if no patch exists, the issue is handled through compensating controls or mitigation, and patch availability does not indicate how urgent or risky the vulnerability is. Option E (number of plugins that detected the vulnerability) is irrelevant because multiple scanners reporting the same CVE is a detection artifact, not a measure of exploit likelihood or business impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EPSS probability score
Why this is correct
The EPSS probability score is a data-driven metric from FIRST that estimates the likelihood a vulnerability will be exploited in the wild within 30 days. It is derived from real-world exploit data, CVE attributes, and threat intelligence, making it a strong indicator of active exploitation risk. As a correct prioritization input, it helps security teams focus on vulnerabilities that are most likely to be attacked, rather than just those with high theoretical severity. This is a valid and important factor for risk-based prioritization.
- ✓
Asset criticality and exposure
Why this is correct
Asset criticality and exposure directly influence the real-world impact of a vulnerability. A flaw affecting a public-facing financial application or a system holding sensitive data presents a far greater business risk than the same vulnerability on an internal, low-value asset. This context is essential for prioritization because it converts raw vulnerability data into organizational risk. A patch manager that ignores this will likely waste resources fixing low-risk issues while leaving high-impact assets vulnerable.
- ✗
Availability of a patch from the vendor
Why it's wrong here
Patch availability is a matter of remediation timing, not prioritization. The existence of a vendor patch does not alter the underlying severity or exploitability of a vulnerability; it simply means you have an option to remediate it. In risk-based prioritization you first decide which vulnerabilities need attention based on likelihood and impact, then schedule the fix. Therefore, patch availability alone is not a valid prioritization criterion, although it can influence the urgency of deploying an existing fix.
- ✓
CVSS base score
Why this is correct
The CVSS base score provides a standardized, vendor-neutral rating (0-10) of a vulnerability's intrinsic severity, based on attack vector, complexity, privileges required, user interaction, and impact on confidentiality, integrity, and availability. It is a widely used starting point for prioritization because it reflects the technical severity that does not depend on any specific environment. However, it does not account for exploitation likelihood or business context, so while it is a correct prioritization factor, it should be combined with other inputs. This score is an objective and repeatable metric suitable for initial triage.
- ✗
Number of plugins that detected the vulnerability
Why it's wrong here
The number of plugins that detected a vulnerability is not a valid prioritization metric, as it is an artifact of scanning tool coverage, not the actual risk. Multiple plugins may flag the same CVE due to overlapping detection rules or false positives, without adding any new information about exploitation likelihood or business impact. Relying on plugin count could cause analysts to chase ambiguous alerts while ignoring genuinely severe issues that only one scanner identified. Consequently, this metric has no bearing on which vulnerabilities should be remediated first.
Go deeper
Related to this question
Learn chapter
Remediation SLAs and Risk Acceptance
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
Key term
Exploit
An exploit is a piece of code, a sequence of commands, or a technique that takes advantage of a vulnerability in a system or software to cause unintended behavior, often for malicious purposes.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.