easyMultiple Choice
CS0-003 Practice Question: A vulnerability scan identifies a critical…
A vulnerability scan identifies a critical unauthenticated remote-code-execution flaw on an internet-facing VPN appliance that is actively exploited in the wild. Several internal-only medium vulnerabilities are also present. What should be remediated first? For business prioritization, Which recommendation gives the best risk-based order of work?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that all vulnerabilities should be patched in order of severity score or age, rather than considering the business context of internet exposure and active exploitation, leading candidates to choose a technically correct but risk-ignorant option like 'start with the oldest medium vulnerability'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patch or mitigate the VPN appliance immediately and verify exposure is removed
The VPN appliance with a critical unauthenticated remote-code-execution flaw that is actively exploited in the wild represents an immediate and severe risk to the organization's security posture. An internet-facing device with such a vulnerability can be compromised by any attacker on the internet without authentication, leading to full system compromise and potential lateral movement into the internal network. Prioritizing remediation of this flaw over internal-only medium vulnerabilities aligns with risk-based vulnerability management principles, as the likelihood and impact of exploitation are far higher.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Patch or mitigate the VPN appliance immediately and verify exposure is removed
Why this is correct
The VPN flaw is unauthenticated remote code execution, internet-facing and actively exploited, so it carries far greater likelihood and impact than the internal medium findings. Patching it first and verifying exposure is removed reflects genuine risk-based prioritisation.
- ✗
Defer all remediation until the monthly patch window
Why it's wrong here
Deferring leaves an actively exploited, unauthenticated RCE reachable from the internet, so compromise can occur before the window. Emergency change procedures exist precisely for such flaws. A monthly patch window suits routine medium findings on internal systems, where no known exploitation or external exposure exists.
- ✗
Start with the oldest medium vulnerability
Why it's wrong here
Age does not reflect exploitability, exposure or impact; an old internal medium finding poses far less risk than an internet-facing flaw under active exploitation. Remediation order should follow risk. Age-based ordering would be defensible only where findings share comparable severity, exposure and exploitation status.
- ✗
Remediate only low-risk internal findings to improve closure rate
Why it's wrong here
Low-risk internal findings do not address the internet-facing, actively exploited RCE, so the exposure persists while effort goes elsewhere. Closure metrics are a reporting artefact, not a risk measure. This approach would suit a backlog-cleanup sprint once critical and high-risk exposures are already remediated.
Go deeper
Related to this question
Learn chapter
Patch and Remediation Workflows
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.