Courseiva
hardMultiple Select

CS0-003 Practice Question: A security analyst is prioritizing…

A security analyst is prioritizing vulnerabilities from a scan. Which TWO factors should be considered to determine the remediation priority? (Select TWO)

⚠ Common exam trap

The CS0-004 exam often tests the misconception that CVSS base score alone determines priority, but the exam emphasizes that exploit availability and asset criticality (here, number of affected systems) are more actionable for remediation prioritization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploit code availability

Exploit code availability is a critical factor because if working exploit code is publicly available, the vulnerability is far more likely to be actively exploited, increasing the risk and urgency for remediation. This directly impacts the likelihood of a breach, making it a key priority driver beyond just the CVSS score.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Exploit code availability

    Why this is correct

    When functional exploit code is publicly available in repositories like Metasploit or Exploit-DB, the technical barrier to entry for attackers drops significantly. This dramatically increases the likelihood of active exploitation, making it a critical, high-priority factor for immediate remediation over vulnerabilities that remain purely theoretical.

  • ✗

    Vendor patch availability

    Why it's wrong here

    While knowing if a patch exists helps plan the remediation strategy, it does not dictate the inherent risk or priority of the vulnerability itself. Analysts must prioritize based on threat severity and exposure; if no patch exists, they must implement compensating controls rather than lowering the vulnerability's priority.

  • ✓

    Number of affected systems

    Why this is correct

    The blast radius and overall organizational impact scale directly with the volume of vulnerable assets. Prioritizing vulnerabilities that affect a large portion of the enterprise infrastructure helps security teams efficiently reduce the overall attack surface and mitigate widespread systemic risk.

  • ✗

    CVSS base score

    Why it's wrong here

    The CVSS base score represents the intrinsic characteristics of a vulnerability but lacks local organizational context, such as threat intelligence or asset criticality. Relying solely on static base scores can lead to inefficient resource allocation, as many high-severity vulnerabilities may not be exploitable in a specific environment.

  • ✗

    Age of the vulnerability

    Why it's wrong here

    The elapsed time since a vulnerability was disclosed does not inherently correlate with its active threat level or potential impact. Legacy vulnerabilities may remain unexploited due to complex pre-requisites, while newly disclosed zero-day vulnerabilities require immediate attention despite having an age of zero.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.