Courseiva

SY0-701 Risk Prioritization Practice Question

A vulnerability scan finds a critical flaw on an internet-facing VPN appliance and says public exploit code is already available. Which issue should be remediated first?

⚠ Common exam trap

The trap here is that candidates may prioritize by severity alone without factoring in exploitability, exposure, or asset criticality—leading them to choose a medium or low finding that is technically less urgent but appears more manageable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A critical flaw on an internet-facing VPN appliance with known exploit code

The critical flaw on an internet-facing VPN appliance with known public exploit code represents the highest risk because it combines a severe vulnerability, direct exposure to the internet, and immediate weaponization potential. VPN appliances are common attack vectors for initial access, and an exploit in the wild means attackers can compromise the device without advanced skills, leading to potential network breach and lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A low-severity finding on an internal test server with no network access

    Why it's wrong here

    An internal test server with no network access cannot be reached by an attacker, so its low-severity flaw poses negligible risk. It is tempting because severity ratings draw attention, but remediation priority here is driven by internet exposure and active exploit availability, not the label alone.

  • ✓

    A critical flaw on an internet-facing VPN appliance with known exploit code

    Why this is correct

    Internet exposure plus publicly available exploit code makes this the highest-risk finding, since attackers can weaponise it immediately without developing their own exploit. Remediation priority follows exploitability and reachability, so this flaw outranks internal or non-exploitable issues.

  • ✗

    A cosmetic configuration warning on a printer management interface

    Why it's wrong here

    A cosmetic warning on a printer interface grants no code execution path and exposes no sensitive data, so it carries minimal risk. It is tempting because it appears on a scan report, but the internet-facing VPN appliance with published exploit code is actively attackable and demands immediate remediation.

  • ✗

    A medium-severity issue on a device that is powered off and not in service

    Why it's wrong here

    A powered-off device not in service runs no code, so the medium-severity issue cannot be exploited until it returns to production. It is tempting because medium severity sounds urgent, yet the internet-facing VPN appliance with public exploit code presents immediate, reachable risk that must be fixed first.

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A scan finds two issues: a critical vulnerability on an internet-facing VPN appliance with public exploit code, and a medium-severity issue on an internal test server. Which should be fixed first?

easy
  • A.The internal test server issue, because test systems are always higher risk.
  • ✓ B.The VPN appliance issue, because it is critical and publicly exploitable.
  • C.Both issues at the same time without assigning a priority.
  • D.Neither issue, because scanners can produce false positives.

Why B: The VPN appliance issue should be fixed first because it is a critical vulnerability on an internet-facing system with publicly available exploit code. This combination means an attacker can directly compromise the appliance from the internet with minimal effort, leading to potential network breach and lateral movement. In contrast, the internal test server is less accessible and poses a lower immediate risk, even though it should still be addressed in due course.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.