easyMultiple Choice
CS0-003 Practice Question: Is the BEST method to prioritize vulnerabilities…
Which of the following is the BEST method to prioritize vulnerabilities for remediation?
⚠ Common exam trap
CS0-004 often tests the difference between CVSS (severity) and actual risk (likelihood + impact), leading candidates to choose CVSS score as the sole prioritization metric.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
By asset criticality and exploitability
Prioritizing vulnerabilities by asset criticality and exploitability is the best method because it combines business impact with the likelihood of exploitation. Asset criticality ensures that vulnerabilities on high-value systems are addressed first, while exploitability (e.g., presence of a public exploit, active exploitation in the wild) indicates urgency. This risk-based approach is more effective than using a single metric like CVSS alone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
By asset criticality and exploitability
Why this is correct
Prioritising by asset criticality and exploitability directs remediation to vulnerabilities on business-critical systems that attackers can realistically exploit, satisfying the stem's demand for the best prioritisation method rather than ranking by raw CVSS score or scan order alone.
- ✗
By availability of patch
Why it's wrong here
Patch availability describes vendor remediation status, not the risk a vulnerability poses, so unpatched-but-unexploited flaws would outrank critical exposed ones. It is tempting because it maps to operational effort, and it would be correct when planning patch deployment windows rather than prioritising risk.
- ✗
By CVSS score
Why it's wrong here
CVSS is a static severity score with no environmental or threat context, so it cannot reflect whether the flaw is exploitable in this estate. It is tempting because it is standardised and easy to sort, and it would be the right basis for initial triage before contextual enrichment.
- ✗
By number of affected hosts
Why it's wrong here
Many hosts with low criticality may be less urgent than few critical hosts.
Go deeper
Related to this question
Learn chapter
Business Email Compromise (BEC) Response
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.