Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

An analyst is reviewing a vulnerability scan report for a containerized application. The scan identifies a critical vulnerability in a base image used by multiple containers. The application is deployed in a Kubernetes cluster with network policies restricting ingress. The vulnerability has a CVSS v3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). However, the EPSS score is 0.001 (0.1%). Which of the following should the analyst prioritize?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Schedule the patch for the next maintenance window because of low EPSS and network controls

Despite high CVSS, the EPSS score indicates extremely low likelihood of exploitation in the wild. The business context and compensating controls (network policies) reduce risk. Therefore, remediation can be scheduled in normal patch cycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a virtual patch via a web application firewall (WAF)

    Why it's wrong here

    A WAF virtual patch shields HTTP-layer application traffic by filtering malicious requests before they reach a web app, but this finding is a vulnerability baked into the container's base image itself, unrelated to inbound web traffic patterns a WAF can inspect. A WAF cannot remediate or compensate for a flaw in the underlying OS packages or libraries the container ships.

  • ✗

    Ignore the vulnerability because it is in a container image

    Why it's wrong here

    Container base image vulnerabilities propagate to every container instantiated from that image, so ignoring it risks widescale exposure across the environment as the image is reused or pushed to new deployments; the finding requires disposition, not silent dismissal, even if compensating controls justify deferring urgency.

  • ✓

    Schedule the patch for the next maintenance window because of low EPSS and network controls

    Why this is correct

    An EPSS score of 0.1% indicates the vulnerability has near-negligible real-world exploitation likelihood in the next 30 days, and the Kubernetes NetworkPolicy restricting ingress further reduces the attack surface by limiting who can even reach the affected containers. Combining low predicted exploitation with existing compensating controls justifies routine remediation timing rather than emergency action, letting the team patch the base image and redeploy during the normal maintenance cycle.

  • ✗

    Immediately patch the vulnerability within 24 hours due to the high CVSS score

    Why it's wrong here

    Reacting to the CVSS 9.8 base score alone ignores the contextual risk data available: EPSS reflects observed exploitation probability and the cluster's network policies provide a compensating control, both of which argue against treating this as a 24-hour emergency. Prioritizing purely on CVSS severity without EPSS and environmental context is a common but flawed triage approach that wastes urgent-response capacity on low-likelihood findings.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.