Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A vulnerability scan finds a critical flaw on an internet-facing SFTP gateway with public exploit code, and a high-severity flaw on an internal lab server that is only reachable from a restricted subnet. Which should be remediated first?

⚠ Common exam trap

The trap here is that candidates fixate on the CVSS severity score (high vs. critical) without factoring in exposure, exploitability, and network segmentation, leading them to incorrectly prioritize the internal server over the internet-facing gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The internet-facing SFTP gateway, because it has higher immediate risk.

The internet-facing SFTP gateway has a critical vulnerability with public exploit code, meaning it is exposed to the entire internet and can be directly attacked without any network restrictions. This creates an immediate and high-likelihood risk of remote code execution or data breach, whereas the internal lab server is isolated to a restricted subnet, significantly reducing its attack surface and exploitability. Remediation priority should be based on risk severity (likelihood × impact), not just CVSS score, making the SFTP gateway the correct first choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The internal lab server, because every high-severity finding should be fixed first.

    Why it's wrong here

    Although the vulnerability may have a high CVSS base score, severity alone does not determine remediation priority. The internal lab server is not directly reachable from untrusted networks, so an attacker would need to first compromise another internal host to reach it. That additional exploit chain reduces its real-world urgency compared to a publicly exposed service, making this option an overly broad rule-of-thumb rather than a risk-based decision.

  • The internet-facing SFTP gateway, because it has higher immediate risk.

    Why this is correct

    The internet-facing SFTP gateway presents the highest immediate risk because it is directly reachable from the internet, placing it on the attack surface with no network boundary protections. If the critical flaw has known exploit code or is actively being leveraged in the wild, the gateway can be compromised without any prior lateral movement. Remediating this asset first directly shrinks the most exposed attack vector, aligning with how security teams prioritize based on exposure and exploitability.

  • Both systems can wait until the next scheduled maintenance window.

    Why it's wrong here

    Waiting until the next scheduled maintenance window leaves the internet-facing gateway continually exposed during the interim period. Any delay increases the probability of exploitation, especially if attackers can automate scanning for this specific vulnerable service. While the internal lab server might plausibly be deferred, the gateway's business risk is time-sensitive and cannot be lumped into a routine patching cycle without accepting significant exposure.

  • Neither system needs urgent action because the lab server is isolated.

    Why it's wrong here

    The lab server's isolation does not negate the gateway's risk because the two systems have entirely different network postures. Isolation may reduce the lab server's attack surface, but the internet-facing SFTP gateway is neither isolated nor protected by such controls. Concluding that no urgent action is needed ignores the gateway's direct exposure and leaves a critical vulnerability open to remote exploitation.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.