Courseiva
Question 564 of 1,013
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A scan reports a critical remote code execution vulnerability on an internet-facing VPN appliance with public proof-of-concept exploit code available. It also reports a critical local privilege escalation on an isolated lab workstation. Patch windows are limited this week. Which should be remediated first?

⚠ Common exam trap

Candidates often assume all critical vulnerabilities are equal and must be patched in order of severity score, ignoring the critical factor of asset exposure and the presence of public exploit code, which dramatically increases the real-world risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The internet-facing VPN appliance because it has higher exposure and exploitability.

The internet-facing VPN appliance presents a higher risk because it is exposed to the public internet and has a known remote code execution vulnerability with public exploit code. This combination of high exposure (attack surface) and high exploitability (availability of proof-of-concept code) significantly increases the likelihood of a successful attack, making it the priority for remediation despite limited patch windows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The internet-facing VPN appliance because it has higher exposure and exploitability.

    Why this is correct

    An externally reachable device with a known exploit and remote code execution risk presents a much larger immediate threat than an isolated lab workstation. Prioritization should consider exposure, exploit maturity, and business impact, not severity score alone. Because the VPN appliance is publicly reachable, compromise could lead directly to remote access into the environment and broader organizational impact.

  • The isolated lab workstation because all critical findings must be patched in numerical order.

    Why it's wrong here

    Patching in numerical order, or by scan severity alone, ignores the key factors of vulnerability risk: exposure, exploit maturity, and business impact. An isolated lab workstation is not reachable from the internet, so despite a critical severity rating, its practical risk is low. Meanwhile, the VPN appliance's remote code execution flaw is directly exploitable from the internet, making it the immediate priority. Effective vulnerability management uses risk-based prioritization, not arbitrary ordering.

  • The internal printer because peripheral devices are often overlooked and therefore most dangerous.

    Why it's wrong here

    While printers have been leveraged in attacks like the 2017 HP bug and can be overlooked, being overlooked does not automatically make a device the most dangerous. An internal printer is only accessible on the internal network, so its attack surface is far smaller than that of the internet-facing VPN appliance. Moreover, the printer is not confirmed to be actively exploited with a known RCE, whereas the VPN is. Prioritization must be based on the actual likelihood and impact of compromise, not on general assumptions about device classes.

  • The lab workstation because local privilege escalation is always more dangerous than remote code execution.

    Why it's wrong here

    Local privilege escalation is a serious threat, but it is not inherently more dangerous than remote code execution. By definition, local privilege escalation requires an attacker to already have a foothold on the system, such as a low-privileged user account. In contrast, remote code execution on an internet-facing VPN appliance can be triggered by an unauthenticated attacker from anywhere, potentially granting immediate access into the internal network. Therefore, the internet-facing RCE presents a much larger immediate threat than a local-only escalation on an isolated lab machine.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.