Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

An analyst is prioritizing vulnerabilities for remediation. The vulnerability has a high CVSS score but is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and has a low EPSS score. The affected asset is a publicly accessible web server handling sensitive customer data. Which factor should the analyst consider as most critical for prioritization?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The business context of asset criticality and exposure

EPSS indicates likelihood of exploitation, but business context (asset criticality and exposure) can override low EPSS if the asset is high-value and exposed. Thus, the analyst should consider the business context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The absence from the KEV catalog

    Why it's wrong here

    While CISA's Known Exploited Vulnerabilities (KEV) catalog is an excellent source for identifying active threats, the absence of a vulnerability from this list does not guarantee safety. Zero-day exploits or highly targeted, non-public attacks may not yet be cataloged by CISA. Relying solely on KEV status can cause an organization to overlook critical, unpatched vulnerabilities that are actively being leveraged in their specific industry.

  • ✓

    The business context of asset criticality and exposure

    Why this is correct

    Effective vulnerability management requires aligning technical severity with business impact. Prioritizing remediation based on asset criticality ensures that high-value systems containing sensitive data or supporting mission-critical operations are patched first. Additionally, evaluating network exposure, such as whether an asset is internet-facing, helps security teams address the most immediate and viable attack vectors.

  • ✗

    The low EPSS score

    Why it's wrong here

    The Exploit Prediction Scoring System (EPSS) estimates the probability of a vulnerability being exploited in the wild within the next 30 days. However, a low EPSS score should not lead to automatic dismissal, as it represents a generalized statistical model rather than localized risk. If a low-EPSS vulnerability exists on a highly critical, externally exposed database, the localized risk remains high enough to warrant immediate remediation.

  • ✗

    The high CVSS score alone

    Why it's wrong here

    The Common Vulnerability Scoring System (CVSS) base score measures the theoretical severity of a vulnerability under ideal conditions but lacks real-world context. Relying solely on a high CVSS score can lead to "patch fatigue" by forcing teams to remediate non-exploitable vulnerabilities on isolated, non-critical systems. Organizations must combine CVSS with threat intelligence and environmental metrics to determine actual operational risk.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.