CS0-003 Vulnerability Management Practice Question
An analyst is reviewing a vulnerability scan report for a containerized application. The scan identifies a critical vulnerability in a base image used by multiple containers. The application is deployed in a Kubernetes cluster with network policies restricting ingress. The vulnerability has a CVSS v3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). However, the EPSS score is 0.001 (0.1%). Which of the following should the analyst prioritize?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Schedule the patch for the next maintenance window because of low EPSS and network controls
Despite high CVSS, the EPSS score indicates extremely low likelihood of exploitation in the wild. The business context and compensating controls (network policies) reduce risk. Therefore, remediation can be scheduled in normal patch cycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a virtual patch via a web application firewall (WAF)
Why it's wrong here
A WAF virtual patch shields HTTP-layer application traffic by filtering malicious requests before they reach a web app, but this finding is a vulnerability baked into the container's base image itself, unrelated to inbound web traffic patterns a WAF can inspect. A WAF cannot remediate or compensate for a flaw in the underlying OS packages or libraries the container ships.
- ✗
Ignore the vulnerability because it is in a container image
Why it's wrong here
Container base image vulnerabilities propagate to every container instantiated from that image, so ignoring it risks widescale exposure across the environment as the image is reused or pushed to new deployments; the finding requires disposition, not silent dismissal, even if compensating controls justify deferring urgency.
- ✓
Schedule the patch for the next maintenance window because of low EPSS and network controls
Why this is correct
An EPSS score of 0.1% indicates the vulnerability has near-negligible real-world exploitation likelihood in the next 30 days, and the Kubernetes NetworkPolicy restricting ingress further reduces the attack surface by limiting who can even reach the affected containers. Combining low predicted exploitation with existing compensating controls justifies routine remediation timing rather than emergency action, letting the team patch the base image and redeploy during the normal maintenance cycle.
- ✗
Immediately patch the vulnerability within 24 hours due to the high CVSS score
Why it's wrong here
Reacting to the CVSS 9.8 base score alone ignores the contextual risk data available: EPSS reflects observed exploitation probability and the cluster's network policies provide a compensating control, both of which argue against treating this as a 24-hour emergency. Prioritizing purely on CVSS severity without EPSS and environmental context is a common but flawed triage approach that wastes urgent-response capacity on low-likelihood findings.
Go deeper
Related to this question
Learn chapter
Network Baseline and Anomaly Detection
Key term
Likelihood
Likelihood is the estimated probability that a specific threat will exploit a vulnerability, causing harm to an IT asset or system.
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.