Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A client asks why a medium-severity finding…

A client asks why a medium-severity finding should be remediated before a high-severity finding. The medium finding is internet-facing and actively exploited; the high finding is isolated in a lab subnet. What is the best explanation?

⚠ Common exam trap

Watch out — candidates often assume CVSS base severity alone dictates remediation order, ignoring the critical role of environmental and temporal metrics, as well as business context like exposure and active exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prioritization should account for exposure and active exploitation, not only the scanner severity.

Risk-based prioritization must consider real-world factors like internet exposure and active exploitation, not just the CVSS base score. A medium-severity finding that is internet-facing and actively exploited poses a higher immediate risk to the organization than a high-severity finding isolated in a lab subnet, which has no external attack surface. This aligns with industry frameworks like CVSS environmental metrics and the FIRST CVSS v3.1 specification, which allow adjusting severity based on attack vector, complexity, and environmental context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Prioritization should account for exposure and active exploitation, not only the scanner severity.

    Why this is correct

    Scanner severity is only a baseline; the actual remediation priority must combine it with exposure and real-world threat data. For example, a medium-severity flaw on an internet-facing asset that is actively exploited in the wild requires faster action than a high-severity issue isolated in a lab with no reachable attack path. Thus, prioritization is a risk-based decision that weighs likelihood and impact, not just the static CVSS label.

  • ✗

    Medium findings must always be fixed before high findings.

    Why it's wrong here

    Remediation order is never dictated by a categorical rule that all medium findings precede high findings. Each finding must be assessed in its specific environmental context, such as the criticality of the affected system, the presence of compensating controls, and the current exploitation activity. For instance, a high-severity vulnerability in a non-critical internal application may be deprioritized over a medium flaw that is publicly exposed and actively targeted, so a blanket ordering is invalid.

  • ✗

    The high finding should be ignored permanently because it is in a lab.

    Why it's wrong here

    Lab assets are not inherently risk-free; they can sit on the same network segment as production, be reachable through misconfigured VPNs, or contain production-like data. Ignoring a high finding in a lab permanently means leaving a potential pivot point or data-exposure risk that future architecture changes could turn into an internet-accessible target. Therefore, the high finding should be tracked under a risk-management process and remediated according to its actual exposure and impact, not automatically dismissed.

  • ✗

    Only CVSS base score matters for remediation order.

    Why it's wrong here

    CVSS base score measures the intrinsic characteristics of a vulnerability, but it deliberately omits environmental and temporal factors that determine real-world urgency. A high base-score flaw can be effectively unexploitable due to network segmentation or existing mitigations, while a moderate base-score issue may be trivial to exploit on an exposed asset with sensitive data. Consequently, remediation order must incorporate the CVSS environmental metrics, exploit code maturity, and organizational risk tolerance, not just the base score.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.