Courseiva
easyMultiple ChoiceObjective-mapped

CS0-003 Practice Question: A vulnerability scan report shows a critical…

A vulnerability scan report shows a critical vulnerability on a web server with a CVSS score of 9.8. The IT manager wants to know the risk to the organization. Which of the following factors should the analyst consider FIRST?

⚠ Common exam trap

CompTIA often tests the distinction between vulnerability severity (CVSS) and organizational risk, trapping candidates who confuse a high CVSS score with automatically high risk without considering asset context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The asset value and business criticality

The CVSS score of 9.8 indicates a critical severity vulnerability, but risk is a function of both severity and business context. The analyst must first assess the asset value and business criticality of the web server because a critical vulnerability on a non-essential server poses lower risk than the same vulnerability on a server handling sensitive data or core business processes. Without this context, the organization cannot prioritize remediation effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The asset value and business criticality

    Why this is correct

    When assessing a critical vulnerability, the asset's value and its criticality to business operations are paramount. This factor directly determines the potential impact of a successful exploit, which is a core component of risk calculation (Risk = Threat x Vulnerability x Impact). A critical vulnerability on a low-value, non-essential asset poses less overall risk than the same vulnerability on a high-value, mission-critical system, dictating immediate prioritization.

  • The vendor's patch release schedule

    Why it's wrong here

    While the vendor's patch release schedule is crucial for planning remediation efforts, it is not the primary factor in initially assessing the risk posed by a critical vulnerability. Knowing when a fix will be available informs the *response* timeline, but it does not change the inherent risk level, which is determined by the vulnerability's severity, the asset's criticality, and the likelihood of exploitation. Risk assessment precedes mitigation planning.

  • The number of exploit attempts in the logs

    Why it's wrong here

    The number of exploit attempts observed in system logs indicates active targeting and increases the *likelihood* component of risk, suggesting an immediate threat. However, this information primarily confirms that a vulnerability is being actively probed, rather than defining the initial risk level. The potential *impact* of a successful exploit, derived from the asset's business criticality, remains the foundational element for prioritizing a critical vulnerability, even without observed attempts.

  • The number of other vulnerabilities on the server

    Why it's wrong here

    While the presence of numerous other vulnerabilities on a server certainly increases its overall attack surface and cumulative risk, this factor does not take precedence over the business criticality of the asset when prioritizing a *critical* vulnerability. A single critical vulnerability on a high-value asset often warrants immediate attention due to its potential for severe impact, regardless of other less severe findings. Prioritization focuses on the most impactful risks first.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.