CS0-003 Vulnerability Management Practice Question
A security analyst is using OpenVAS to perform a vulnerability scan of an internal network. The scan completes and generates a report listing several vulnerabilities. What is the next step in the vulnerability lifecycle?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritization
After discovery (scanning), the next step is prioritization of vulnerabilities based on risk, exploitability, and business impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Prioritization
Why this is correct
Immediately after scan results are generated, analysts must rank findings by exploitability, asset criticality, and business context so limited remediation resources are directed at the highest-impact vulnerabilities first, which is prioritization.
- ✗
Verification
Why it's wrong here
Verification confirms whether a reported vulnerability is genuine or already patched, and it occurs after analysis, not directly after the scan. The raw OpenVAS output needs triage first to establish which findings warrant validation. Verification would be correct once candidate vulnerabilities have been identified and require confirmation.
- ✗
Reporting
Why it's wrong here
Reporting is a communication activity, not the immediate lifecycle step after a scan completes. The findings must first be analysed and validated to separate true positives from false positives. Reporting would be correct when presenting confirmed, prioritised results to management or stakeholders for decision-making.
- ✗
Remediation
Why it's wrong here
Remediation follows prioritisation and validation, not the raw scan output. The scan has only produced findings; they must first be analysed and confirmed as genuine before fixes are scheduled. Remediation is the later stage where patches or configuration changes are applied to close validated vulnerabilities.
Go deeper
Related to this question
Learn chapter
Network Traffic Analysis
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
OpenVAS
OpenVAS is an open-source vulnerability scanner that helps IT professionals identify security weaknesses in networks, systems, and applications.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.