mediumMultiple Select
CS0-003 Practice Question: A security analyst is prioritizing…
A security analyst is prioritizing vulnerabilities for remediation. Which TWO factors should be considered HIGHEST when determining prioritization? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests that candidates confuse vulnerability age with exploit maturity, but age alone is irrelevant without evidence of active exploitation or a functional exploit in the wild.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CVSS base score
The CVSS base score provides a standardized, quantitative measure of a vulnerability's severity based on intrinsic characteristics like attack vector and complexity. Prioritizing by CVSS score ensures that remediation efforts focus on vulnerabilities with the highest potential impact, aligning with industry best practices for risk-based vulnerability management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CVSS base score
Why this is correct
The Common Vulnerability Scoring System (CVSS) base score provides a standardized, quantitative framework for assessing the inherent severity of a vulnerability. It evaluates immutable characteristics such as exploitability metrics and impact metrics, allowing analysts to establish an objective baseline for risk prioritization.
- ✗
Number of false positives associated with the scan
Why it's wrong here
While identifying and filtering out false positives is a critical step in scan data sanitization, the sheer volume of false positives does not dictate the actual risk or remediation priority of legitimate vulnerabilities. Prioritizing based on this metric would waste valuable cycles on non-existent threats rather than addressing verified, high-severity exposures.
- ✗
System owner's preference
Why it's wrong here
Relying on a system owner's subjective preference introduces human bias and ignores objective risk metrics like threat intelligence and business impact. Effective vulnerability management must be data-driven, aligning remediation efforts with standardized severity scores, asset criticality, and active exploit data rather than personal convenience or departmental politics.
- ✗
Age of the vulnerability
Why it's wrong here
The chronological age of a vulnerability does not inherently correlate with its risk level or exploitability. A newly discovered zero-day vulnerability with active exploits poses a far greater immediate threat than an older, low-severity vulnerability that has remained unpatched due to its low impact and lack of public exploit code.
- ✓
Known exploit availability
Why this is correct
The availability of public exploit code or active exploitation in the wild dramatically escalates the real-world risk of a vulnerability. When threat actors have weaponized code readily accessible, such as in Metasploit or CISA's Known Exploited Vulnerabilities catalog, the likelihood of compromise increases, making these vulnerabilities top candidates for immediate remediation.
Go deeper
Related to this question
Learn chapter
Nessus Vulnerability Scanner
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Attack vector
An attack vector is the specific path or method a cyber attacker uses to gain unauthorized access to a computer system or network.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.