Courseiva
easyMultiple Choice

CS0-003 Practice Question: Is the BEST method to prioritize vulnerabilities…

Which of the following is the BEST method to prioritize vulnerabilities for remediation?

⚠ Common exam trap

CS0-004 often tests the difference between CVSS (severity) and actual risk (likelihood + impact), leading candidates to choose CVSS score as the sole prioritization metric.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

By asset criticality and exploitability

Prioritizing vulnerabilities by asset criticality and exploitability is the best method because it combines business impact with the likelihood of exploitation. Asset criticality ensures that vulnerabilities on high-value systems are addressed first, while exploitability (e.g., presence of a public exploit, active exploitation in the wild) indicates urgency. This risk-based approach is more effective than using a single metric like CVSS alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    By asset criticality and exploitability

    Why this is correct

    Prioritising by asset criticality and exploitability directs remediation to vulnerabilities on business-critical systems that attackers can realistically exploit, satisfying the stem's demand for the best prioritisation method rather than ranking by raw CVSS score or scan order alone.

  • ✗

    By availability of patch

    Why it's wrong here

    Patch availability describes vendor remediation status, not the risk a vulnerability poses, so unpatched-but-unexploited flaws would outrank critical exposed ones. It is tempting because it maps to operational effort, and it would be correct when planning patch deployment windows rather than prioritising risk.

  • ✗

    By CVSS score

    Why it's wrong here

    CVSS is a static severity score with no environmental or threat context, so it cannot reflect whether the flaw is exploitable in this estate. It is tempting because it is standardised and easy to sort, and it would be the right basis for initial triage before contextual enrichment.

  • ✗

    By number of affected hosts

    Why it's wrong here

    Many hosts with low criticality may be less urgent than few critical hosts.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.