CS0-003 Vulnerability Management Practice Question
A vulnerability management team is prioritizing vulnerabilities for remediation. They have a list of vulnerabilities with different characteristics. According to best practices, which TWO factors should be considered when prioritizing vulnerabilities? (Select TWO.)
⚠ Common exam trap
The trap is treating CVSS base score as the sole prioritization metric; candidates who select it ignore that business criticality and active exploitation (KEV) are what convert technical severity into actual organizational risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The asset's criticality to the business
Option B is correct because an asset's criticality to the business determines the real-world impact of exploitation, so a high-severity vulnerability on a mission-critical server should be remediated before the same vulnerability on a low-value test machine. Option D is correct because the CISA Known Exploited Vulnerabilities (KEV) catalog identifies vulnerabilities that are actively exploited in the wild, which is a strong signal to prioritize them regardless of other factors. The CVSS base score (A) reflects intrinsic severity but not business context or exploitation activity, so it is only one input rather than a standalone prioritization factor. Patch availability (C) affects remediation timing but does not by itself indicate risk priority, and the number of open ports (E) is an attack-surface indicator, not a standard vulnerability prioritization criterion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CVSS base score
Why it's wrong here
The CVSS base score is a useful, standardized severity metric, but it is calculated in a vacuum and does not incorporate any context about how the vulnerability is exploited in the wild or what business assets it affects. A high CVSS score does not automatically mean the vulnerability should be remediated first; attackers often chain lower-severity weaknesses in ways that bypass the score's assumptions. Prioritization must blend CVSS with threat intelligence and the specific value of the target system to the organization.
- ✓
The asset's criticality to the business
Why this is correct
Asset criticality is the correct primary driver for prioritization because it directly captures the potential business impact if confidentiality, integrity, or availability is compromised. A vulnerability on a server that processes financial transactions or contains protected health information poses far greater risk than the same CVE on an internet-facing demo server with no sensitive data. This aligns with risk-based vulnerability management, where risk equals the likelihood of exploitation multiplied by the consequence to the business.
- ✗
The availability of a patch
Why it's wrong here
The availability of a patch is a remediation constraint, not a prioritization factor; you first determine which vulnerabilities pose the greatest risk, then you decide how to address them based on whether a patch, workaround, or compensating control exists. A vulnerability with no available patch may actually be higher priority because it requires immediate mitigation planning, such as network segmentation or enhanced monitoring. Prioritization answers 'what matters most,' while patch availability answers 'how can we fix it.'
- ✓
Whether the vulnerability is listed in the CISA KEV catalog
Why this is correct
Inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog is a correct, high-priority signal because it means the vulnerability has been observed exploited in real-world attacks, not just theoretically scored. This evidence-driven intelligence overrides CVSS-only approaches, as many KEV entries have low or medium base scores yet are actively weaponized by threat actors. An exploitable-in-the-wild vulnerability on a critical asset should take precedence over a 'critical' CVSS vulnerability with no known exploitation.
- ✗
The number of open ports on the asset
Why it's wrong here
The number of open ports on an asset is not a direct prioritization factor because it only describes the attack surface size, not the exploitability or business impact of any specific vulnerability. A server with three open ports could host a publicly reachable, zero-day-vulnerable service, while a server with fifty open ports might run fully patched, non-sensitive services. Effective prioritization requires analyzing the vulnerability present on a given port and the asset's role, not merely counting the ports.
Go deeper
Related to this question
Learn chapter
Patch and Remediation Workflows
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.