Courseiva
Vulnerability Management →mediumMultiple Select

CS0-003 Vulnerability Management Practice Question

A vulnerability management team is prioritizing vulnerabilities for remediation. They have a list of vulnerabilities with different characteristics. According to best practices, which TWO factors should be considered when prioritizing vulnerabilities? (Select TWO.)

⚠ Common exam trap

The trap is treating CVSS base score as the sole prioritization metric; candidates who select it ignore that business criticality and active exploitation (KEV) are what convert technical severity into actual organizational risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The asset's criticality to the business

Option B is correct because an asset's criticality to the business determines the real-world impact of exploitation, so a high-severity vulnerability on a mission-critical server should be remediated before the same vulnerability on a low-value test machine. Option D is correct because the CISA Known Exploited Vulnerabilities (KEV) catalog identifies vulnerabilities that are actively exploited in the wild, which is a strong signal to prioritize them regardless of other factors. The CVSS base score (A) reflects intrinsic severity but not business context or exploitation activity, so it is only one input rather than a standalone prioritization factor. Patch availability (C) affects remediation timing but does not by itself indicate risk priority, and the number of open ports (E) is an attack-surface indicator, not a standard vulnerability prioritization criterion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The CVSS base score

    Why it's wrong here

    The CVSS base score is a useful, standardized severity metric, but it is calculated in a vacuum and does not incorporate any context about how the vulnerability is exploited in the wild or what business assets it affects. A high CVSS score does not automatically mean the vulnerability should be remediated first; attackers often chain lower-severity weaknesses in ways that bypass the score's assumptions. Prioritization must blend CVSS with threat intelligence and the specific value of the target system to the organization.

  • ✓

    The asset's criticality to the business

    Why this is correct

    Asset criticality is the correct primary driver for prioritization because it directly captures the potential business impact if confidentiality, integrity, or availability is compromised. A vulnerability on a server that processes financial transactions or contains protected health information poses far greater risk than the same CVE on an internet-facing demo server with no sensitive data. This aligns with risk-based vulnerability management, where risk equals the likelihood of exploitation multiplied by the consequence to the business.

  • ✗

    The availability of a patch

    Why it's wrong here

    The availability of a patch is a remediation constraint, not a prioritization factor; you first determine which vulnerabilities pose the greatest risk, then you decide how to address them based on whether a patch, workaround, or compensating control exists. A vulnerability with no available patch may actually be higher priority because it requires immediate mitigation planning, such as network segmentation or enhanced monitoring. Prioritization answers 'what matters most,' while patch availability answers 'how can we fix it.'

  • ✓

    Whether the vulnerability is listed in the CISA KEV catalog

    Why this is correct

    Inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog is a correct, high-priority signal because it means the vulnerability has been observed exploited in real-world attacks, not just theoretically scored. This evidence-driven intelligence overrides CVSS-only approaches, as many KEV entries have low or medium base scores yet are actively weaponized by threat actors. An exploitable-in-the-wild vulnerability on a critical asset should take precedence over a 'critical' CVSS vulnerability with no known exploitation.

  • ✗

    The number of open ports on the asset

    Why it's wrong here

    The number of open ports on an asset is not a direct prioritization factor because it only describes the attack surface size, not the exploitability or business impact of any specific vulnerability. A server with three open ports could host a publicly reachable, zero-day-vulnerable service, while a server with fifty open ports might run fully patched, non-sensitive services. Effective prioritization requires analyzing the vulnerability present on a given port and the asset's role, not merely counting the ports.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.