Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security team is using EPSS scores and CISA KEV catalog to prioritize vulnerabilities. Which combination of factors would indicate the HIGHEST priority for remediation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

High EPSS score and presence in KEV catalog

CISA KEV catalog contains vulnerabilities known to be exploited in the wild, and a high EPSS score indicates a high probability of exploitation. Together, they indicate the highest priority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Medium CVSS score and high asset criticality

    Why it's wrong here

    While high asset criticality dictates the potential impact of a breach, a medium CVSS score combined with a lack of EPSS or KEV data means there is no active threat intelligence indicating the vulnerability is currently being targeted. Without empirical evidence of real-world exploitation, prioritizing this asset over actively exploited vulnerabilities leads to inefficient resource allocation.

  • ✓

    High EPSS score and presence in KEV catalog

    Why this is correct

    This combination represents the highest remediation priority because the CISA KEV catalog confirms the vulnerability is currently being exploited in the wild, while a high EPSS score mathematically predicts a high probability of imminent exploitation. Leveraging both threat-centric metrics allows security analysts to transition from theoretical severity to active risk-based patching.

  • ✗

    High CVSS score and low EPSS score

    Why it's wrong here

    A high CVSS score reflects a severe theoretical impact if exploited, but a low EPSS score indicates a very low statistical probability of actual exploitation in the near future. Relying solely on CVSS without KEV or EPSS validation often results in patch fatigue, as security teams waste cycles fixing severe but unexploitable vulnerabilities.

  • ✗

    Low CVSS score and presence in KEV catalog

    Why it's wrong here

    Although presence in the CISA KEV catalog demands urgent attention because the vulnerability is actively exploited, a low CVSS score indicates that the technical impact of a successful compromise is minimal. When compared to vulnerabilities that boast both a high EPSS score and KEV status, this scenario represents a lower overall risk profile.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.