Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A vulnerability management team is prioritizing remediation of several vulnerabilities. They have access to EPSS scores and the CISA KEV catalog. Which factor should they consider FIRST when deciding which vulnerability to remediate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The vulnerability listed in the CISA Known Exploited Vulnerabilities catalog

The CISA KEV catalog contains vulnerabilities that are actively exploited in the wild. These pose immediate risk and should be addressed before others, regardless of EPSS score or other factors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vulnerability with the highest base CVSS score

    Why it's wrong here

    While the Common Vulnerability Scoring System (CVSS) base score provides a standardized measure of a vulnerability's intrinsic severity, it does not reflect real-world threat intelligence or active exploitation. Prioritizing solely on CVSS base scores often leads to patch fatigue because many high-severity vulnerabilities are never actually exploited in the wild. Security teams must combine CVSS with temporal and environmental metrics to determine actual risk.

  • ✓

    The vulnerability listed in the CISA Known Exploited Vulnerabilities catalog

    Why this is correct

    The Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities with documented, active exploitation in the wild. Remediation of these flaws must be prioritized because they represent immediate, validated threat vectors that adversaries are currently leveraging to compromise systems. Addressing KEV-listed vulnerabilities directly reduces the organization's active attack surface far more effectively than theoretical risk models.

  • ✗

    The vulnerability affecting the most critical asset

    Why it's wrong here

    Although asset criticality is a vital component of risk-based vulnerability management, focusing exclusively on critical assets can leave the perimeter vulnerable to lateral movement. An actively exploited vulnerability on a lower-priority asset can serve as an initial entry point for attackers to pivot to high-value targets. Therefore, active exploitation status takes precedence over asset classification during immediate prioritization triage.

  • ✗

    The vulnerability with the highest EPSS score

    Why it's wrong here

    The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited within the next 30 days based on historical data and threat feeds. While EPSS is an excellent predictive tool for proactive patching, it remains a statistical forecast rather than a confirmation of current malicious activity. A vulnerability listed in the CISA KEV catalog represents a confirmed, ongoing threat, making its remediation far more urgent than a high-probability prediction.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.