Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A scan finds two issues: a critical flaw on a lab server reachable only through VPN, and a high-severity flaw on an internet-facing file transfer appliance with active exploitation in the wild. Which should be remediated first?

⚠ Common exam trap

Watch out — candidates often assume CVSS severity alone dictates remediation order, ignoring that exploitability and exposure (e.g., internet-facing vs. VPN-restricted) are critical factors in risk-based prioritization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The internet-facing file transfer appliance, because exploitability and exposure increase risk.

The internet-facing file transfer appliance with active exploitation in the wild presents a higher risk because it is directly exposed to untrusted networks and has a known exploit that attackers are actively using. Even though the lab server has a critical severity rating, its reachability only through VPN significantly reduces its attack surface and likelihood of exploitation. Risk is a function of both severity and exploitability/exposure, so the actively exploited, internet-facing asset should be remediated first.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The lab server, because critical severity is always higher than high severity.

    Why it's wrong here

    CVSS scores convey technical severity, but they do not directly translate to risk; risk also depends on the asset's exposure, the current threat landscape, and the potential business impact. A critical flaw on an internal lab server that is reachable only through the corporate network and shows no signs of active exploitation is often less urgent than a high-severity flaw on an internet-facing system that is already being exploited by attackers. In risk-based prioritization, numeric severity is merely one input; a high-severity flaw with active exploitation and public exposure will usually be addressed first because it presents a greater likelihood of a successful breach.

  • The internet-facing file transfer appliance, because exploitability and exposure increase risk.

    Why this is correct

    The internet-facing appliance should be fixed first because it is exposed to untrusted users and already being exploited in the wild. Risk-based prioritization considers not only severity but also exposure, exploit availability, and business impact. A high-severity flaw with active exploitation on a public-facing system is usually more urgent than a critical flaw on a restricted lab server.

  • Both issues at the same time, because prioritization is unnecessary when two findings are present.

    Why it's wrong here

    Treating two findings as inherently equal ignores the reality that remediation resources are limited and that vulnerabilities carry different levels of actual risk. Even a smaller set of findings still requires prioritization: the security team must decide where to apply patches, compensating controls, or other mitigations based on which issue poses the greatest immediate threat. Ignoring risk-based prioritization and attempting to fix both at once can lead to wasted effort or, worse, leaving the more exploitable vulnerability open while time is spent on a lower-risk lab server. The correct approach is to evaluate each finding against criteria such as exposure, exploitability, asset criticality, and threat intelligence before scheduling remediation.

  • The lab server, because systems behind VPN are always more trusted than public systems.

    Why it's wrong here

    A VPN reduces the attack surface, but it does not make a system automatically trustworthy or low-risk; VPN access can be compromised, credentials can be stolen, and insider threats or lateral movement can still reach the lab server. Meanwhile, the file transfer appliance is directly exposed to the internet, meaning it is continuously probed by scanners and attackers with no network boundary between them and the service. The higher risk comes from the combination of internet accessibility and known active exploitation—factors that increase the likelihood of a compromise far more than a mere critical severity rating behind a VPN. Thus, believing that VPN placement always outweighs public exposure is a misconception that ignores the probabilistic nature of risk assessment and the current threat context.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A vulnerability scan finds two issues: a critical deserialization flaw on a non-production lab server behind a VPN, and a high-severity privilege escalation flaw on the production jump server that administrators use to reach the rest of the environment. Which should be remediated first?

medium
  • A.The lab server flaw, because critical severity always comes first
  • B.The jump server flaw, because it affects a production administrative access point
  • C.Neither issue, because VPN access reduces the need for urgent remediation
  • D.The lab server flaw, because non-production systems are always easier to patch later

Why B: The jump server flaw must be remediated first because it is a high-severity privilege escalation vulnerability on a production system that administrators use as a gateway to the entire environment. Compromise of this jump server would give an attacker administrative access to all connected production systems, making the business impact far greater than the critical deserialization flaw on an isolated non-production lab server. In risk-based prioritization, severity alone is insufficient; the asset's role, exposure, and potential blast radius must be considered.

Variation 2. A vulnerability scan finds a critical flaw on an internet-facing SFTP gateway with public exploit code, and a high-severity flaw on an internal lab server that is only reachable from a restricted subnet. Which should be remediated first?

easy
  • A.The internal lab server, because every high-severity finding should be fixed first.
  • B.The internet-facing SFTP gateway, because it has higher immediate risk.
  • C.Both systems can wait until the next scheduled maintenance window.
  • D.Neither system needs urgent action because the lab server is isolated.

Why B: The internet-facing SFTP gateway has a critical vulnerability with public exploit code, meaning it is exposed to the entire internet and can be directly attacked without any network restrictions. This creates an immediate and high-likelihood risk of remote code execution or data breach, whereas the internal lab server is isolated to a restricted subnet, significantly reducing its attack surface and exploitability. Remediation priority should be based on risk severity (likelihood × impact), not just CVSS score, making the SFTP gateway the correct first choice.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.