hardMultiple Choice
CISA KEV & EPSS Prioritization: Why Threat Intelligence Trumps CVSS
A vulnerability report has 900 findings. One medium CVSS vulnerability is listed in CISA KEV and has high EPSS; several high CVSS issues are not exploitable in the environment. What should the analyst recommend? For business prioritization, Which recommendation gives the best risk-based order of work?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that CVSS base score alone determines priority, but the trap here is that candidates ignore the KEV/EPSS context and choose to remediate high-CVSS issues first, failing to apply risk-based prioritization that accounts for real-world exploitability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize the KEV/high-EPSS issue after confirming asset exposure
It combines threat intelligence (CISA KEV and high EPSS) with environmental context (asset exposure) to prioritize the vulnerability that is actively exploited and likely to be used in attacks, even though its CVSS base score is medium. This aligns with risk-based vulnerability management, which weights exploitability and business impact over raw severity scores.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Always sort only by CVSS base score
Why it's wrong here
CVSS is useful but incomplete without exploitability and exposure.
- ✗
Remediate alphabetically by CVE ID
Why it's wrong here
CVE order has no risk meaning.
- ✓
Prioritize the KEV/high-EPSS issue after confirming asset exposure
Why this is correct
Prioritising the KEV/high-EPSS finding reflects genuine exploitation risk rather than raw CVSS severity, since CISA KEV confirms active exploitation and high EPSS predicts imminent attacks. Confirming asset exposure first filters out non-reachable systems, satisfying the stem's requirement for a risk-based order that discounts the several high-CVSS but non-exploitable issues.
- ✗
Remediate only vulnerabilities with vendor logos in the report
Why it's wrong here
Vendor branding is irrelevant to risk.
Go deeper
Related to this question
Learn chapter
Threat Emulation and Purple Team Exercises
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.