Courseiva
Question 816 of 1,013
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A scan finds two issues: a critical vulnerability on an internet-facing VPN appliance with public exploit code, and a medium-severity issue on an internal test server. Which should be fixed first?

⚠ Common exam trap

Many candidates assume all vulnerabilities must be fixed in order of severity alone, ignoring the critical factor of asset exposure and exploitability, which CompTIA emphasizes in risk-based prioritization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The VPN appliance issue, because it is critical and publicly exploitable.

The VPN appliance issue should be fixed first because it is a critical vulnerability on an internet-facing system with publicly available exploit code. This combination means an attacker can directly compromise the appliance from the internet with minimal effort, leading to potential network breach and lateral movement. In contrast, the internal test server is less accessible and poses a lower immediate risk, even though it should still be addressed in due course.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The internal test server issue, because test systems are always higher risk.

    Why it's wrong here

    The internal test server issue is not automatically the highest risk because test systems typically reside on an internal network segment, limiting exposure to the public internet. The critical VPN appliance flaw, in contrast, is directly reachable from the internet and has known exploit code, making an actual breach far more imminent. In risk-based prioritization, asset exposure and exploitability outweigh the type or role of the system.

  • The VPN appliance issue, because it is critical and publicly exploitable.

    Why this is correct

    The VPN appliance issue should be addressed first because it combines a critical severity rating with direct internet exposure and publicly available exploit code, creating an immediate and realistic attack vector. This scenario represents a high likelihood of compromise with high impact, often allowing full network access. Prioritizing this issue aligns with common frameworks like the CVSS base score and EPSS, where exploitability and network reachability significantly elevate remediation urgency.

  • Both issues at the same time without assigning a priority.

    Why it's wrong here

    Addressing both issues simultaneously with no priority is inefficient and dangerous because security resources are finite and response teams must focus on minimizing the greatest risk first. The two vulnerabilities likely differ in severity, exploitability, and blast radius, making a risk-based triage essential. Treating them equally could delay remediation of the critical external VPN flaw, leaving an exploitable entry point open while internal test server issues carry far less immediate threat.

  • Neither issue, because scanners can produce false positives.

    Why it's wrong here

    Ignoring both findings due to potential false positives is negligent because the critical VPN vulnerability is internet-facing and has exploit code, which dramatically increases the chance it is real and actively targeted. While scanner false positives do occur, the correct action is to validate the finding, not dismiss it outright. By the time manual confirmation is performed, an attacker could already leverage the flaw; therefore, urgent verification and mitigation are required.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.