Courseiva
easyMultiple Choice

CS0-003 Practice Question: A vulnerability scan identifies a critical…

A vulnerability scan identifies a critical unauthenticated remote-code-execution flaw on an internet-facing VPN appliance that is actively exploited in the wild. Several internal-only medium vulnerabilities are also present. What should be remediated first? For business prioritization, Which recommendation gives the best risk-based order of work?

⚠ Common exam trap

The CS0-004 exam often tests the misconception that all vulnerabilities should be patched in order of severity score or age, rather than considering the business context of internet exposure and active exploitation, leading candidates to choose a technically correct but risk-ignorant option like 'start with the oldest medium vulnerability'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch or mitigate the VPN appliance immediately and verify exposure is removed

The VPN appliance with a critical unauthenticated remote-code-execution flaw that is actively exploited in the wild represents an immediate and severe risk to the organization's security posture. An internet-facing device with such a vulnerability can be compromised by any attacker on the internet without authentication, leading to full system compromise and potential lateral movement into the internal network. Prioritizing remediation of this flaw over internal-only medium vulnerabilities aligns with risk-based vulnerability management principles, as the likelihood and impact of exploitation are far higher.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Patch or mitigate the VPN appliance immediately and verify exposure is removed

    Why this is correct

    The VPN flaw is unauthenticated remote code execution, internet-facing and actively exploited, so it carries far greater likelihood and impact than the internal medium findings. Patching it first and verifying exposure is removed reflects genuine risk-based prioritisation.

  • ✗

    Defer all remediation until the monthly patch window

    Why it's wrong here

    Deferring leaves an actively exploited, unauthenticated RCE reachable from the internet, so compromise can occur before the window. Emergency change procedures exist precisely for such flaws. A monthly patch window suits routine medium findings on internal systems, where no known exploitation or external exposure exists.

  • ✗

    Start with the oldest medium vulnerability

    Why it's wrong here

    Age does not reflect exploitability, exposure or impact; an old internal medium finding poses far less risk than an internet-facing flaw under active exploitation. Remediation order should follow risk. Age-based ordering would be defensible only where findings share comparable severity, exposure and exploitation status.

  • ✗

    Remediate only low-risk internal findings to improve closure rate

    Why it's wrong here

    Low-risk internal findings do not address the internet-facing, actively exploited RCE, so the exposure persists while effort goes elsewhere. Closure metrics are a reporting artefact, not a risk measure. This approach would suit a backlog-cleanup sprint once critical and high-risk exposures are already remediated.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.