CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing the results of a vulnerability scan and notices that several vulnerabilities have high CVSS scores but low EPSS scores. The analyst also cross-references the CISA Known Exploited Vulnerabilities (KEV) catalog and finds that none of these vulnerabilities are listed. Which approach should the analyst take when prioritizing remediation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize based on EPSS scores and KEV status, but also consider business context.
EPSS predicts the likelihood of exploitation, and KEV lists vulnerabilities known to be exploited in the wild. High CVSS but low EPSS and not in KEV suggests the vulnerability may be severe but unlikely to be exploited currently. However, business context such as asset criticality and exposure should be considered; if the asset is critical and exposed, remediation should still be prioritized despite low exploitation likelihood.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remediate vulnerabilities with high CVSS scores only if they are internet-facing.
Why it's wrong here
While internet-facing assets present an immediate attack surface, focusing exclusively on them ignores the risk of lateral movement. Internal systems often house highly sensitive data, such as active directory domain controllers or database servers, which could be compromised if an attacker establishes an initial foothold. Therefore, ignoring internal high-severity vulnerabilities creates a massive blind spot in defense-in-depth strategies.
- ✓
Prioritize based on EPSS scores and KEV status, but also consider business context.
Why this is correct
Combining the Exploit Prediction Scoring System (EPSS) and CISA's Known Exploited Vulnerabilities (KEV) catalog allows analysts to focus on threats with active, real-world exploitation activity. Integrating business context ensures that remediation efforts are directed toward high-value assets that directly impact organizational operations. This risk-based approach optimizes resource allocation and significantly reduces actual organizational exposure compared to relying solely on static severity scores.
- ✗
Remediate only vulnerabilities found in the KEV catalog.
Why it's wrong here
Relying solely on CISA's KEV catalog is insufficient because it only tracks vulnerabilities known to be actively exploited in the wild. An organization may still host critical, proprietary, or legacy systems vulnerable to zero-day exploits or targeted attacks that have not yet been cataloged. Neglecting these non-KEV vulnerabilities can leave severe security gaps in an organization's unique internal infrastructure.
- ✗
Remediate all vulnerabilities with CVSS scores above 9.0 immediately.
Why it's wrong here
Relying strictly on CVSS scores above 9.0 leads to "vulnerability fatigue" because CVSS measures theoretical severity rather than active threat likelihood. Many high-severity vulnerabilities are never exploited in the wild due to mitigating controls or lack of public exploit code. Prioritizing purely by CVSS scores can waste valuable engineering resources on theoretical risks while leaving lower-scoring, actively exploited vulnerabilities unpatched.
Go deeper
Related to this question
Learn chapter
Patch and Remediation Workflows
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.