SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A vulnerability scan reports three findings: a critical remote code execution issue on an internet-facing VPN appliance with a public exploit, a high-severity local privilege escalation on an isolated lab PC, and a medium-severity outdated browser plug-in on a workstation used for training. Which finding should be remediated first?
⚠ Common exam trap
The trap here is that candidates may prioritize based solely on severity score or common attack vectors (like browser plug-ins) without considering the combination of exposure, exploit availability, and the critical nature of the vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The internet-facing VPN appliance, because it combines critical severity, exposure, and public exploit availability.
The internet-facing VPN appliance should be remediated first because it combines a critical severity rating, direct exposure to the internet, and a publicly available exploit. This creates an immediate and high-probability risk of remote code execution, which could lead to full compromise of the network perimeter. In contrast, the other findings are isolated or lower severity, making them less urgent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The isolated lab PC, because local privilege escalation is always the highest technical severity.
Why it's wrong here
Local privilege escalation may be severe in isolation, but the isolated lab PC is not reachable from the internet and likely contains no production data; an attacker would already need a foothold inside the lab to exploit it. The CVSS label alone does not encode exposure, compensating controls, or business impact, so it cannot be the sole basis for priority. In contrast, the internet-facing VPN appliance combines critical severity, public exploit code, and direct reachability, making it the clear first remediation target.
- ✓
The internet-facing VPN appliance, because it combines critical severity, exposure, and public exploit availability.
Why this is correct
The VPN appliance should be first because it is exposed to the internet, has a critical vulnerability, and has known exploit code available. That combination significantly increases the likelihood and impact of compromise, making it the most urgent remediation target.
- ✗
The training workstation, because browser plug-ins are common entry points for attackers.
Why it's wrong here
Browser plug-ins are indeed a frequent initial access vector, but this specific finding is only medium severity and affects a training workstation, which is a lower-value, less-exposed target than an edge security device. Attackers are more likely to exploit a critical, internet-facing VPN flaw with publicly available exploit code, because it requires no user interaction and can compromise a trusted network gateway. Remediation should be driven by a combination of severity, exposure, and known exploitation, not by the popularity of an attack technique.
- ✗
None of them, because all vulnerability findings should wait for the next planned maintenance cycle.
Why it's wrong here
Deferring all vulnerability remediation to the next maintenance cycle ignores the fundamental principle of risk-based prioritization: critical, internet-facing, and publicly exploitable vulnerabilities require immediate action, not schedule convenience. The VPN appliance finding presents an extremely high probability of successful remote compromise with significant business impact, whereas lower-severity or isolated issues do not pose comparable risk. Waiting on all findings treats every vulnerability as equal, which leads to higher overall exposure and contradicts standard vulnerability management frameworks such as CVSS and EPSS.
Go deeper
Related to this question
Learn chapter
Network-Based Attacks
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.