Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst reviews a vulnerability scan report and identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is 'Network', attack complexity is 'Low', privileges required is 'None', user interaction is 'None', scope is 'Unchanged', and all three CIA impacts are 'High'. Which additional factor should the analyst prioritize when deciding whether to apply a patch or a compensating control?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The EPSS score for the vulnerability

The EPSS score estimates the likelihood of exploitation in the wild, which helps prioritize remediation. CVSS alone does not indicate active exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The number of affected hosts

    Why it's wrong here

    Although the total count of affected hosts helps determine the overall scope and resource allocation for remediation efforts, it does not measure the immediate threat level of the vulnerability itself. Prioritization must focus on the likelihood of active exploitation and the criticality of the exposed assets rather than sheer volume.

  • ✓

    The EPSS score for the vulnerability

    Why this is correct

    The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited in the wild within the next 30 days. This data-driven metric allows analysts to prioritize high-probability threats immediately and decide whether to deploy rapid patches or implement temporary compensating controls.

  • ✗

    The OS type of the affected system

    Why it's wrong here

    Identifying the operating system is necessary for selecting the correct patch package and ensuring system compatibility during deployment. However, the OS type alone does not indicate the severity or active exploitation potential of a vulnerability, making it secondary to threat-intelligence-driven metrics like EPSS.

  • ✗

    The vendor's patch release date

    Why it's wrong here

    The release date of a vendor's patch indicates how long a fix has been available and helps track SLA compliance for remediation timelines. It does not, however, reflect the real-world risk, exploitability, or active threat landscape associated with the vulnerability, which are critical for risk-based prioritization.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.