Vulnerability Prioritization: Remediating by CVSS Severity
Exhibit
Vulnerability review summary: Finding A: CVE-2025-1184 | DMZ web server | Internet-facing | Remote code execution | Exploit in the wild | Patch available Finding B: CVE-2025-4420 | Engineering laptop | Internal-only lab VLAN | CVSS 9.8 | Requires local access | No network path Finding C: CVE-2025-6011 | File server | Internal network | Requires authenticated user | Compensating ACL restricts access Finding D: CVE-2025-7044 | Backup appliance | Internal network | No patch yet | Vendor says issue is unreachable from network
Based on the exhibit, which finding should be remediated first?
Quick Answer
The answer is Finding A, because it has the highest CVSS score of 9.8, placing it in the critical severity range. In vulnerability prioritization, CVSS scores directly guide remediation order by quantifying risk based on exploitability and impact; a score of 9.8 indicates a vulnerability that can be exploited remotely without authentication, often enabling remote code execution. On the Security+ SY0-701 exam, this concept tests your ability to apply risk-based prioritization in a scenario with multiple findings, where the common trap is to focus on the number of vulnerabilities rather than their severity. Remember that CVSS scores above 9.0 are critical and should always be remediated first, regardless of other factors. A useful memory tip is “9.8 is great for attackers, so patch it first.”
⚠ Common exam trap
The trap here is that candidates might choose a finding solely based on the highest CVSS score, without considering other risk factors such as exploitability, asset criticality, or active exploitation. CompTIA expects you to prioritize based on overall risk, not just severity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Finding A
Finding A is prioritized first because it represents the highest overall risk when considering exploitability, potential impact, and asset criticality. While CVSS scores are a factor, remediation decisions should weigh the likelihood of exploitation and the severity of consequences; Finding A poses an immediate and severe threat that could lead to significant compromise, thereby requiring urgent action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Finding A
Why this is correct
Finding A combines internet exposure, remote code execution, and active exploitation in the wild, making it the most urgent risk even if another item has a slightly higher CVSS score. Exposure and exploitability matter more than score alone. A patch is available, so remediation can reduce the window of opportunity quickly. In Security+ style prioritization, reachable, actively exploited weaknesses on public-facing systems rise to the top.
- ✗
Finding B
Why it's wrong here
Finding B has a high score, but it requires local access and sits on an internal lab VLAN with no network path.
- ✗
Finding C
Why it's wrong here
Finding C affects a file server, but the compensating ACL limits exposure and the issue requires authenticated access.
- ✗
Finding D
Why it's wrong here
Finding D is concerning, but the vendor states the flaw is currently unreachable from the network and there is no patch yet.
Go deeper
Related to this question
Learn chapter
Network-Based Attacks
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Based on the exhibit, which finding should the security team remediate first?
easy- A.LAP09 because user devices are always the easiest to patch
- ✓ B.WEB01 because it is internet-facing and has a critical exploitable vulnerability
- C.PRN01 because firmware issues can affect many users
- D.FILE02 because internal servers are always more important than public ones
Why B: WEB01 is internet-facing and has a critical exploitable vulnerability, meaning an attacker can directly compromise it from the public internet with minimal effort. This represents the highest risk because it combines high likelihood (exploit available) with high impact (full compromise of a public-facing server). Remediating this first aligns with the principle of prioritizing externally exposed systems with known critical flaws over internal or less severe issues.
Variation 2. Based on the exhibit, which issue should be remediated FIRST? The team can only fully fix one issue today. Management wants the choice that best reduces real-world risk, not just the highest severity score.
hard- ✓ A.Internet-facing VPN appliance
- B.Internal HR file server
- C.Lab workstation
- D.DMZ reporting server
Why A: The Internet-facing VPN appliance is the highest priority because it is directly exposed to untrusted networks (the Internet), making it the most likely entry point for attackers. A compromise here could lead to full network access, bypassing all other security controls, which represents the greatest real-world risk regardless of its severity score.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.