CS0-003 Vulnerability Management Practice Question
An analyst is prioritizing vulnerabilities for remediation. The vulnerability has a high CVSS score but is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and has a low EPSS score. The affected asset is a publicly accessible web server handling sensitive customer data. Which factor should the analyst consider as most critical for prioritization?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The business context of asset criticality and exposure
EPSS indicates likelihood of exploitation, but business context (asset criticality and exposure) can override low EPSS if the asset is high-value and exposed. Thus, the analyst should consider the business context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The absence from the KEV catalog
Why it's wrong here
While CISA's Known Exploited Vulnerabilities (KEV) catalog is an excellent source for identifying active threats, the absence of a vulnerability from this list does not guarantee safety. Zero-day exploits or highly targeted, non-public attacks may not yet be cataloged by CISA. Relying solely on KEV status can cause an organization to overlook critical, unpatched vulnerabilities that are actively being leveraged in their specific industry.
- ✓
The business context of asset criticality and exposure
Why this is correct
Effective vulnerability management requires aligning technical severity with business impact. Prioritizing remediation based on asset criticality ensures that high-value systems containing sensitive data or supporting mission-critical operations are patched first. Additionally, evaluating network exposure, such as whether an asset is internet-facing, helps security teams address the most immediate and viable attack vectors.
- ✗
The low EPSS score
Why it's wrong here
The Exploit Prediction Scoring System (EPSS) estimates the probability of a vulnerability being exploited in the wild within the next 30 days. However, a low EPSS score should not lead to automatic dismissal, as it represents a generalized statistical model rather than localized risk. If a low-EPSS vulnerability exists on a highly critical, externally exposed database, the localized risk remains high enough to warrant immediate remediation.
- ✗
The high CVSS score alone
Why it's wrong here
The Common Vulnerability Scoring System (CVSS) base score measures the theoretical severity of a vulnerability under ideal conditions but lacks real-world context. Relying solely on a high CVSS score can lead to "patch fatigue" by forcing teams to remediate non-exploitable vulnerabilities on isolated, non-critical systems. Organizations must combine CVSS with threat intelligence and environmental metrics to determine actual operational risk.
Go deeper
Related to this question
Learn chapter
Penetration Testing vs Vulnerability Assessment
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.