Courseiva
hardMultiple Select

CS0-003 Practice Question: A security analyst is prioritizing…

A security analyst is prioritizing vulnerabilities for remediation. The analyst has the following information: a vulnerability with a CVSS score of 9.0 that affects a public-facing web server, and a vulnerability with a CVSS score of 7.5 that affects an internal database server with sensitive data. Which two factors should the analyst consider when prioritizing? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the misconception that CVSS score alone determines priority, whereas the correct approach combines CVSS with threat intelligence (exploit availability) and asset criticality/exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The presence of known exploits in the wild.

The presence of known exploits in the wild directly impacts the likelihood of a vulnerability being weaponized. Even a high CVSS score (e.g., 9.0) may be less urgent if no exploit exists, while a lower-scored vulnerability (e.g., 7.5) with active exploitation poses an immediate threat. This aligns with the CVSS environmental metrics and threat intelligence integration in vulnerability management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The presence of known exploits in the wild.

    Why this is correct

    Vulnerabilities with active, publicly available exploits in the wild pose an immediate threat because the barrier to entry for attackers is significantly lowered. Prioritizing these flaws aligns with threat-intelligence-driven vulnerability management, ensuring that organizations defend against active, real-world campaigns before addressing theoretical risks.

  • ✗

    The vendor's patch release date.

    Why it's wrong here

    While the release date of a patch helps track remediation timelines, it does not indicate the severity or active exploitation status of a vulnerability. Older patches are not inherently more or less critical to apply than newer ones; prioritization must rely on risk metrics rather than chronological release order.

  • ✓

    The asset's exposure and criticality.

    Why this is correct

    Effective vulnerability prioritization requires environmental context, specifically evaluating whether an affected system is public-facing and hosts mission-critical data. A low-severity vulnerability on an internet-accessible database server often demands faster remediation than a critical vulnerability on an isolated, non-essential testing workstation.

  • ✗

    The number of open ports on each server.

    Why it's wrong here

    The sheer quantity of open ports on a server is a general attack surface metric, but it does not correlate directly to the severity of specific software vulnerabilities. A system with many secure, well-configured open ports may be less risky than a system with a single open port running a highly vulnerable legacy service.

  • ✗

    The vulnerability publication date.

    Why it's wrong here

    The date a vulnerability was first disclosed or assigned a CVE does not reflect its current risk profile or likelihood of exploitation. A newly discovered vulnerability might remain unexploited for years, whereas an older, well-documented vulnerability might suddenly see a spike in automated exploit attempts across the internet.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.