mediumMultiple SelectObjective-mapped
CS0-003 Practice Question: Which three of the following are effective…
Which three of the following are effective techniques for prioritizing vulnerabilities for remediation in a vulnerability management program? (Choose three.)
⚠ Common exam trap
CompTIA often tests the misconception that CVSS base scores alone are sufficient for prioritization, when in fact they must be combined with asset criticality, threat context, and compensating controls to reflect true organizational risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlating vulnerabilities with active exploit campaigns and threat intelligence feeds
Correlating vulnerabilities with active exploit campaigns and threat intelligence feeds is effective because it prioritizes vulnerabilities that are currently being exploited in the wild, which directly reduces the risk of a breach. This approach aligns remediation with real-world attacker behavior rather than theoretical severity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Applying the Common Vulnerability Scoring System (CVSS) base score as the sole prioritization metric
Why it's wrong here
The CVSS base score is an intrinsic severity metric that describes the static properties of a vulnerability (attack vector, complexity, privileges, user interaction, and impact), but it deliberately excludes environmental context and temporal factors. Relying on it as the sole prioritization metric ignores whether the vulnerability is currently being exploited, criticality of the affected asset, and any compensating controls already in place. This leads to misallocation of remediation resources, where a low-CVSS but actively exploited weakness on a critical system may be deprioritized in favor of a high-CVSS issue that is never exploited and has little real-world impact.
- ✓
Correlating vulnerabilities with active exploit campaigns and threat intelligence feeds
Why this is correct
Correlating vulnerabilities with active exploit campaigns and threat intelligence feeds injects real-time, attacker-centered context into the prioritization process. Intelligence feeds provide indicators of compromise, exploitability (e.g., published exploit code, proof-of-concept), and observations of active exploitation observed by security researchers or incident responders. This technique aligns remediation efforts with the immediate threat landscape, ensuring that organizations patch the specific weaknesses that adversaries are currently leveraging, rather than only relying on static severity scores. It directly supports a risk-based vulnerability management program by adjusting priorities based on current attacker behavior and known exploit activity.
- ✓
Using asset criticality ratings derived from business impact analysis (BIA)
Why this is correct
Asset criticality ratings derived from a business impact analysis (BIA) classify systems according to the potential financial, operational, operational, reputational, or regulatory impact if they are imapcted by a security incident. By mapping each vulnerability to the asset it affects, organizations can prioritize remediation of the most valuable or business-essential systems first, even when a vulnerability's raw severity score is moderate. This contextual approach recognizes that protecting critical data and services is more important than systematically eliminating every flaw on low-value infrastructure, thereby optimizing the risk reduction achieved by a limited remediation budget.
- ✗
Prioritizing vulnerabilities based solely on the age of the CVE
Why it's wrong here
The age of a CVE is a poor proxy for actual risk because vulnerability exploitation lifetimes vary dramatically — some new vulnerabilities are exploited as zero-days within hours of publication, while many older CVEs are never exploited and may already be mitigated by subsequent updates or security controls. Attackers frequently target recently disclosed vulnerabilities because targets may not yet have patched, whereas older flaws often have widespread coverage or effective workarounds. Prioritizing by age alone disregards the underlying exploitability, the asset's value, and threat intelligence, leading to wasted patches on irrelevant historical issues while missing imminent active threats.
- ✓
Incorporating compensating controls that may reduce the effective risk of a vulnerability
Why this is correct
Compensating controls are alternate safeguards that reduce the effective risk of a vulnerability when an inherent patch or primary control cannot be applied, such as network ACLs, segmentation, or host-based firewalls that restrict access to a vulnerable service. Incorporating these into prioritization correctly adjusts the risk score downward, since an already-mitigated weakness poses less immediate danger than an unmitigated, directly reachable vulnerability on a critical system. This prevents organizations from spending scarce patch cycles on issues that are effectively remediated through other means, and instead focuses remediation on the residual risk that remains despite existing controls.
- ✗
Focusing remediation efforts exclusively on vulnerabilities with a CVSS score of 9.0 or higher
Why it's wrong here
Focusing exclusively on vulnerabilities with a CVSS score of 9.0 or higher is misleading because severity is only one dimension of risk — a high score does not guarantee exploitability, active exploitation, or relevance to your environment. Vulnerabilities with scores below 9.0 are commonly exploited by attackers, especially when they affect exposed assets or have public exploit code, while many 9.0-plus flaws may be difficult to exploit or require specific conditions that do not exist in your infrastructure. An exclusive high-score focus leaves the organization exposed to lower-scoring but realistically exploitable weaknesses, creating a false sense of security and violating the core principle of risk-based prioritization.
Go deeper
Related to this question
Learn chapter
Threat Intelligence and Threat Hunting
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.