Courseiva
mediumMultiple Select

CS0-003 Practice Question: A security analyst is prioritizing…

A security analyst is prioritizing vulnerabilities for remediation. Which TWO factors should be considered HIGHEST when determining prioritization? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests that candidates confuse vulnerability age with exploit maturity, but age alone is irrelevant without evidence of active exploitation or a functional exploit in the wild.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CVSS base score

The CVSS base score provides a standardized, quantitative measure of a vulnerability's severity based on intrinsic characteristics like attack vector and complexity. Prioritizing by CVSS score ensures that remediation efforts focus on vulnerabilities with the highest potential impact, aligning with industry best practices for risk-based vulnerability management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CVSS base score

    Why this is correct

    The Common Vulnerability Scoring System (CVSS) base score provides a standardized, quantitative framework for assessing the inherent severity of a vulnerability. It evaluates immutable characteristics such as exploitability metrics and impact metrics, allowing analysts to establish an objective baseline for risk prioritization.

  • ✗

    Number of false positives associated with the scan

    Why it's wrong here

    While identifying and filtering out false positives is a critical step in scan data sanitization, the sheer volume of false positives does not dictate the actual risk or remediation priority of legitimate vulnerabilities. Prioritizing based on this metric would waste valuable cycles on non-existent threats rather than addressing verified, high-severity exposures.

  • ✗

    System owner's preference

    Why it's wrong here

    Relying on a system owner's subjective preference introduces human bias and ignores objective risk metrics like threat intelligence and business impact. Effective vulnerability management must be data-driven, aligning remediation efforts with standardized severity scores, asset criticality, and active exploit data rather than personal convenience or departmental politics.

  • ✗

    Age of the vulnerability

    Why it's wrong here

    The chronological age of a vulnerability does not inherently correlate with its risk level or exploitability. A newly discovered zero-day vulnerability with active exploits poses a far greater immediate threat than an older, low-severity vulnerability that has remained unpatched due to its low impact and lack of public exploit code.

  • ✓

    Known exploit availability

    Why this is correct

    The availability of public exploit code or active exploitation in the wild dramatically escalates the real-world risk of a vulnerability. When threat actors have weaponized code readily accessible, such as in Metasploit or CISA's Known Exploited Vulnerabilities catalog, the likelihood of compromise increases, making these vulnerabilities top candidates for immediate remediation.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.