Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing the results of a vulnerability scan and notices that several vulnerabilities have high CVSS scores but low EPSS scores. The analyst also cross-references the CISA Known Exploited Vulnerabilities (KEV) catalog and finds that none of these vulnerabilities are listed. Which approach should the analyst take when prioritizing remediation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prioritize based on EPSS scores and KEV status, but also consider business context.

EPSS predicts the likelihood of exploitation, and KEV lists vulnerabilities known to be exploited in the wild. High CVSS but low EPSS and not in KEV suggests the vulnerability may be severe but unlikely to be exploited currently. However, business context such as asset criticality and exposure should be considered; if the asset is critical and exposed, remediation should still be prioritized despite low exploitation likelihood.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remediate vulnerabilities with high CVSS scores only if they are internet-facing.

    Why it's wrong here

    While internet-facing assets present an immediate attack surface, focusing exclusively on them ignores the risk of lateral movement. Internal systems often house highly sensitive data, such as active directory domain controllers or database servers, which could be compromised if an attacker establishes an initial foothold. Therefore, ignoring internal high-severity vulnerabilities creates a massive blind spot in defense-in-depth strategies.

  • ✓

    Prioritize based on EPSS scores and KEV status, but also consider business context.

    Why this is correct

    Combining the Exploit Prediction Scoring System (EPSS) and CISA's Known Exploited Vulnerabilities (KEV) catalog allows analysts to focus on threats with active, real-world exploitation activity. Integrating business context ensures that remediation efforts are directed toward high-value assets that directly impact organizational operations. This risk-based approach optimizes resource allocation and significantly reduces actual organizational exposure compared to relying solely on static severity scores.

  • ✗

    Remediate only vulnerabilities found in the KEV catalog.

    Why it's wrong here

    Relying solely on CISA's KEV catalog is insufficient because it only tracks vulnerabilities known to be actively exploited in the wild. An organization may still host critical, proprietary, or legacy systems vulnerable to zero-day exploits or targeted attacks that have not yet been cataloged. Neglecting these non-KEV vulnerabilities can leave severe security gaps in an organization's unique internal infrastructure.

  • ✗

    Remediate all vulnerabilities with CVSS scores above 9.0 immediately.

    Why it's wrong here

    Relying strictly on CVSS scores above 9.0 leads to "vulnerability fatigue" because CVSS measures theoretical severity rather than active threat likelihood. Many high-severity vulnerabilities are never exploited in the wild due to mitigating controls or lack of public exploit code. Prioritizing purely by CVSS scores can waste valuable engineering resources on theoretical risks while leaving lower-scoring, actively exploited vulnerabilities unpatched.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.