easyMultiple Choice
CS0-003 Practice Question: A vulnerability scan identifies a critical…
A vulnerability scan identifies a critical unauthenticated remote-code-execution flaw on an internet-facing VPN appliance that is actively exploited in the wild. Several internal-only medium vulnerabilities are also present. What should be remediated first? For validation, Which action should be taken before closing or downgrading the finding?
⚠ Common exam trap
The CS0-004 exam often tests the candidate's ability to apply risk-based prioritization over a simple 'patch oldest first' or 'close low-hanging fruit' mentality, trapping those who ignore the criticality of actively exploited, internet-facing vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patch or mitigate the VPN appliance immediately and verify exposure is removed
The critical unauthenticated remote-code-execution (RCE) vulnerability on the internet-facing VPN appliance poses an immediate and active threat, as it is being exploited in the wild. According to the CVSS scoring system and industry best practices (e.g., PCI DSS, NIST SP 800-115), vulnerabilities that are remotely exploitable, have high impact, and are actively exploited must be prioritized over internal-only medium-severity issues. Remediating this flaw first reduces the attack surface exposed to the internet and prevents potential compromise of the entire network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Patch or mitigate the VPN appliance immediately and verify exposure is removed
Why this is correct
An unauthenticated critical vulnerability on an internet-facing VPN appliance represents an extremely high-risk exposure, demanding immediate attention. This scenario indicates a direct path for attackers to gain unauthorized access to the internal network without needing credentials, making it a prime target for active exploitation. Prioritizing this remediation is crucial because its internet exposure and critical impact far outweigh other findings, necessitating an emergency patch or mitigation to remove the threat immediately.
- ✗
Start with the oldest medium vulnerability
Why it's wrong here
Prioritizing remediation solely based on the age of a vulnerability, especially one classified as medium risk, is an ineffective risk management strategy. While older vulnerabilities might indicate neglect, the immediate threat posed by an actively exploited, critical, internet-facing vulnerability far surpasses the urgency of an aged, medium-risk internal finding. Effective prioritization must consider exploitability, exposure, and potential impact over mere age or internal classification.
- ✗
Remediate only low-risk internal findings to improve closure rate
Why it's wrong here
Focusing remediation efforts exclusively on low-risk internal findings to inflate closure rates is a misguided approach to vulnerability management. This strategy creates a false sense of security by improving metrics without addressing the most significant threats to the organization. Ignoring critical, externally exposed vulnerabilities in favor of easily closed, minor internal issues leaves the organization highly susceptible to severe breaches, demonstrating poor risk-based prioritization.
- ✗
Defer all remediation until the monthly patch window
Why it's wrong here
Deferring all remediation until a scheduled monthly patch window is an unacceptable response for a critical, unauthenticated vulnerability on an internet-facing VPN appliance, especially if it's actively exploited. Such a severe threat requires an immediate, out-of-band emergency response to prevent or stop ongoing compromise. Adhering strictly to a fixed schedule for critical, internet-facing remote code execution (RCE) vulnerabilities demonstrates a lack of understanding of modern threat landscapes and incident response principles.
Go deeper
Related to this question
Learn chapter
Identity-Based Attack Patterns: Pass-the-Hash, Kerberoasting
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.