Courseiva
hardMultiple Choice

CISA KEV & EPSS Prioritization: Why Threat Intelligence Trumps CVSS

A vulnerability report has 900 findings. One medium CVSS vulnerability is listed in CISA KEV and has high EPSS; several high CVSS issues are not exploitable in the environment. What should the analyst recommend? For business prioritization, Which recommendation gives the best risk-based order of work?

⚠ Common exam trap

The CS0-004 exam often tests the misconception that CVSS base score alone determines priority, but the trap here is that candidates ignore the KEV/EPSS context and choose to remediate high-CVSS issues first, failing to apply risk-based prioritization that accounts for real-world exploitability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prioritize the KEV/high-EPSS issue after confirming asset exposure

It combines threat intelligence (CISA KEV and high EPSS) with environmental context (asset exposure) to prioritize the vulnerability that is actively exploited and likely to be used in attacks, even though its CVSS base score is medium. This aligns with risk-based vulnerability management, which weights exploitability and business impact over raw severity scores.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Always sort only by CVSS base score

    Why it's wrong here

    CVSS is useful but incomplete without exploitability and exposure.

  • ✗

    Remediate alphabetically by CVE ID

    Why it's wrong here

    CVE order has no risk meaning.

  • ✓

    Prioritize the KEV/high-EPSS issue after confirming asset exposure

    Why this is correct

    Prioritising the KEV/high-EPSS finding reflects genuine exploitation risk rather than raw CVSS severity, since CISA KEV confirms active exploitation and high EPSS predicts imminent attacks. Confirming asset exposure first filters out non-reachable systems, satisfying the stem's requirement for a risk-based order that discounts the several high-CVSS but non-exploitable issues.

  • ✗

    Remediate only vulnerabilities with vendor logos in the report

    Why it's wrong here

    Vendor branding is irrelevant to risk.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.