Courseiva
hardMultiple Choice

CS0-003 Practice Question: A security analyst is prioritizing…

A security analyst is prioritizing vulnerabilities for remediation. The following vulnerabilities have been identified:

Vulnerability A: CVSS v3.1 Base Score 9.8 (Critical), no known exploit, affects internet-facing web server. Vulnerability B: CVSS v3.1 Base Score 7.5 (High), exploit available, affects internal database server. Vulnerability C: CVSS v3.1 Base Score 6.1 (Medium), exploit available, affects internal file server. Vulnerability D: CVSS v3.1 Base Score 4.0 (Medium), no known exploit, affects internal workstation.

Which vulnerability should be remediated FIRST?

⚠ Common exam trap

The CS0-004 exam often tests the misconception that an available exploit always outweighs a higher CVSS score, but the correct prioritization must consider both severity and exposure, especially for internet-facing systems with Critical scores.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability A

Vulnerability A has a CVSS v3.1 Base Score of 9.8 (Critical) and affects an internet-facing web server, which is directly exposed to external threats. Even though no known exploit exists, the high severity and exposure mean that a zero-day or future exploit could cause severe impact, making it the highest priority for remediation according to risk-based prioritization frameworks like CVSS and NIST SP 800-40.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability D

    Why it's wrong here

    Vulnerability D, categorized as low severity and residing on an internal system, presents the lowest immediate risk. Its minimal potential impact and limited exposure mean it is unlikely to be actively exploited by external threat actors without prior network penetration. Therefore, it warrants the lowest priority in remediation efforts, allowing security teams to focus on more critical issues first.

  • ✗

    Vulnerability C

    Why it's wrong here

    Vulnerability C, despite being classified as medium severity, is located on an internal system, which significantly reduces its immediate exploitability by external attackers. While it could potentially lead to moderate impact if an attacker gains internal access, its lack of direct internet exposure makes it a lower priority compared to vulnerabilities that are externally accessible. Remediation can be scheduled after addressing higher-risk items.

  • ✗

    Vulnerability B

    Why it's wrong here

    Vulnerability B, identified as high severity, is present on an internal system, meaning an attacker would first need to breach the network perimeter to exploit it. Although its potential impact is significant once exploited, its internal nature reduces the urgency compared to vulnerabilities directly exposed to the internet. Prioritizing this over critical external threats would misallocate resources, as the attack surface is more contained.

  • ✓

    Vulnerability A

    Why this is correct

    Vulnerability A represents the highest immediate risk due to its critical severity rating and presence on an internet-facing system. This combination means it is highly susceptible to exploitation by external threat actors, potentially leading to severe data breaches, system compromise, or service disruption without requiring prior internal access. Remediation of such a vulnerability must be the absolute top priority to mitigate the most significant and accessible threat to the organization.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.