CS0-003 Vulnerability Management Practice Question
A security team is using EPSS scores and CISA KEV catalog to prioritize vulnerabilities. Which combination of factors would indicate the HIGHEST priority for remediation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High EPSS score and presence in KEV catalog
CISA KEV catalog contains vulnerabilities known to be exploited in the wild, and a high EPSS score indicates a high probability of exploitation. Together, they indicate the highest priority.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Medium CVSS score and high asset criticality
Why it's wrong here
While high asset criticality dictates the potential impact of a breach, a medium CVSS score combined with a lack of EPSS or KEV data means there is no active threat intelligence indicating the vulnerability is currently being targeted. Without empirical evidence of real-world exploitation, prioritizing this asset over actively exploited vulnerabilities leads to inefficient resource allocation.
- ✓
High EPSS score and presence in KEV catalog
Why this is correct
This combination represents the highest remediation priority because the CISA KEV catalog confirms the vulnerability is currently being exploited in the wild, while a high EPSS score mathematically predicts a high probability of imminent exploitation. Leveraging both threat-centric metrics allows security analysts to transition from theoretical severity to active risk-based patching.
- ✗
High CVSS score and low EPSS score
Why it's wrong here
A high CVSS score reflects a severe theoretical impact if exploited, but a low EPSS score indicates a very low statistical probability of actual exploitation in the near future. Relying solely on CVSS without KEV or EPSS validation often results in patch fatigue, as security teams waste cycles fixing severe but unexploitable vulnerabilities.
- ✗
Low CVSS score and presence in KEV catalog
Why it's wrong here
Although presence in the CISA KEV catalog demands urgent attention because the vulnerability is actively exploited, a low CVSS score indicates that the technical impact of a successful compromise is minimal. When compared to vulnerabilities that boast both a high EPSS score and KEV status, this scenario represents a lower overall risk profile.
Go deeper
Related to this question
Learn chapter
Executive Security Reporting
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.