Question 1,103 of 1,013
SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Exhibit
Weekly vulnerability scan summary: 1. WEB01 - Public web server - Critical CVE with known exploit and no compensating control 2. FILE02 - Internal file server - Medium severity missing patch 3. LAP09 - User laptop - Low severity browser plug-in issue 4. PRN01 - Network printer - Informational firmware notice only
Based on the exhibit, which finding should the security team remediate first?
⚠ Common exam trap
The trap here is that candidates prioritize based on ease of remediation (A) or internal importance (D) instead of applying a risk-based approach that considers both the severity of the vulnerability and the exposure of the asset.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WEB01 because it is internet-facing and has a critical exploitable vulnerability
WEB01 is internet-facing and has a critical exploitable vulnerability, meaning an attacker can directly compromise it from the public internet with minimal effort. This represents the highest risk because it combines high likelihood (exploit available) with high impact (full compromise of a public-facing server). Remediating this first aligns with the principle of prioritizing externally exposed systems with known critical flaws over internal or less severe issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LAP09 because user devices are always the easiest to patch
Why it's wrong here
LAP09 is a low-severity finding on an internal user device, and while patching laptops may be operationally convenient, ease of remediation does not determine security priority. A low-severity vulnerability with no known exploit and limited network exposure presents far less immediate risk than a critical, internet-facing vulnerability that is actively exploitable. Prioritizing by attack surface and exploitability, the web server must come first despite any patching convenience.
- ✓
WEB01 because it is internet-facing and has a critical exploitable vulnerability
Why this is correct
WEB01 should be remediated first because it is public-facing, rated critical, and already has a known exploit. Exposure and exploitability greatly increase risk, so this finding has the highest immediate urgency. When patching resources are limited, internet-facing critical vulnerabilities are typically prioritized before internal or low-severity issues.
- ✗
PRN01 because firmware issues can affect many users
Why it's wrong here
PRN01 is flagged as informational, meaning it lacks a severity rating and does not correspond to a known exploitable vulnerability or a concrete attack path. A printer firmware issue might require local network access or physical interaction, and while it could affect availability for many users, that is an operational concern rather than an urgent security risk. Remediation should focus on the critical web server vulnerability, which exposes the organization to immediate remote compromise.
- ✗
FILE02 because internal servers are always more important than public ones
Why it's wrong here
FILE02 is a medium-severity finding on an internal file server, but 'internal' does not automatically increase risk—it usually reduces the attack surface because firewalls and network segmentation provide compensating controls. The file server issue is not rated critical and does not appear to be publicly reachable, so its potential impact is bounded to an already trusted network zone. An internet-facing server with a critical, known-exploitable vulnerability possesses both a wider attack surface and a higher likelihood of compromise, making it the correct remediation target.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.