Courseiva
Vulnerability ManagementmediumMultiple SelectObjective-mapped

CS0-003 Vulnerability Management Practice Question

A security analyst is prioritizing vulnerabilities discovered during a scan. Which TWO factors should the analyst consider as part of business context to determine remediation priority? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Asset exposure

Asset criticality (how important the asset is to the business) and exposure (whether the asset is internet-facing or accessible to attackers) are key business context factors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Asset exposure

    Why this is correct

    Exposure determines the likelihood of attack, considering whether the asset is internet-facing or reachable by potential adversaries. It directly influences the probability of exploitation, making it a fundamental factor in prioritizing vulnerabilities. Without exposure, even a critical vulnerability on an internal system poses less immediate risk. Therefore, asset exposure is the primary determinant for prioritizing remediation efforts.

  • CVSS base score

    Why it's wrong here

    The CVSS base score measures the intrinsic technical severity of a vulnerability, such as attack vector and complexity, but ignores the context of the asset's exposure or business value. It provides a standardized metric for comparing vulnerabilities, yet lacks environmental and temporal factors that affect real-world risk. Consequently, relying solely on CVSS can lead to misprioritization, as a high-severity vulnerability may target a non-critical asset with minimal exposure.

  • Patch availability

    Why it's wrong here

    Patch availability is a remediation characteristic, indicating whether a fix exists, but it does not determine the urgency of the risk. Having an available patch does not reduce the likelihood of exploitation before the patch is applied, and prioritization still requires assessing the asset's exposure and criticality. Additionally, patches may require testing and change management, so availability alone does not dictate which vulnerability to address first.

  • Exploit availability

    Why it's wrong here

    Exploit availability refers to whether a functional exploit exists in the wild, which increases the threat but is only one element of threat context. It does not incorporate asset-specific business context, such as the importance of the data or the system's exposure. While a known exploit should elevate attention, prioritization must still consider whether the affected asset is exposed and how critical it is to operations.

  • Asset criticality

    Why this is correct

    Asset criticality reflects the value and importance of an asset to business processes, confidentiality, integrity, and availability, or compliance requirements. Critical assets should receive higher prioritization because their compromise can cause severe operational or financial impact. However, criticality alone does not account for the likelihood of attack; exposure and exploit availability are also necessary to fully assess risk in vulnerability prioritization.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.