hardMultiple Select
CS0-003 Practice Question: A security analyst is prioritizing…
A security analyst is prioritizing vulnerabilities from a scan. Which TWO factors should be considered to determine the remediation priority? (Select TWO)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that CVSS base score alone determines priority, but the exam emphasizes that exploit availability and asset criticality (here, number of affected systems) are more actionable for remediation prioritization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploit code availability
Exploit code availability is a critical factor because if working exploit code is publicly available, the vulnerability is far more likely to be actively exploited, increasing the risk and urgency for remediation. This directly impacts the likelihood of a breach, making it a key priority driver beyond just the CVSS score.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Exploit code availability
Why this is correct
When functional exploit code is publicly available in repositories like Metasploit or Exploit-DB, the technical barrier to entry for attackers drops significantly. This dramatically increases the likelihood of active exploitation, making it a critical, high-priority factor for immediate remediation over vulnerabilities that remain purely theoretical.
- ✗
Vendor patch availability
Why it's wrong here
While knowing if a patch exists helps plan the remediation strategy, it does not dictate the inherent risk or priority of the vulnerability itself. Analysts must prioritize based on threat severity and exposure; if no patch exists, they must implement compensating controls rather than lowering the vulnerability's priority.
- ✓
Number of affected systems
Why this is correct
The blast radius and overall organizational impact scale directly with the volume of vulnerable assets. Prioritizing vulnerabilities that affect a large portion of the enterprise infrastructure helps security teams efficiently reduce the overall attack surface and mitigate widespread systemic risk.
- ✗
CVSS base score
Why it's wrong here
The CVSS base score represents the intrinsic characteristics of a vulnerability but lacks local organizational context, such as threat intelligence or asset criticality. Relying solely on static base scores can lead to inefficient resource allocation, as many high-severity vulnerabilities may not be exploitable in a specific environment.
- ✗
Age of the vulnerability
Why it's wrong here
The elapsed time since a vulnerability was disclosed does not inherently correlate with its active threat level or potential impact. Legacy vulnerabilities may remain unexploited due to complex pre-requisites, while newly disclosed zero-day vulnerabilities require immediate attention despite having an age of zero.
Go deeper
Related to this question
Learn chapter
Penetration Testing vs Vulnerability Assessment
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Likelihood
Likelihood is the estimated probability that a specific threat will exploit a vulnerability, causing harm to an IT asset or system.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.