SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Exhibit
Vulnerability scan summary: 1) Internet-facing VPN appliance CVSS: 8.8 Exploit status: public proof-of-concept available Exposure: reachable from the internet Compensating controls: none 2) Internal HR file server CVSS: 9.8 Exploit status: no public exploit yet Exposure: reachable only from the employee VLAN Compensating controls: segmented network and MFA for admin access 3) Lab workstation CVSS: 10.0 Exploit status: public exploit available Exposure: isolated lab VLAN with no routing to production 4) DMZ reporting server CVSS: 7.5 Exploit status: public exploit available Exposure: internet-reachable, but protected by WAF and IP allowlisting
Based on the exhibit, which issue should be remediated FIRST?
The team can only fully fix one issue today. Management wants the choice that best reduces real-world risk, not just the highest severity score.
⚠ Common exam trap
The trap here is that candidates often fixate on the highest CVSS severity score (e.g., a critical vulnerability on the internal server) rather than considering the attack surface and likelihood of exploitation, which is the core of risk-based prioritization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Internet-facing VPN appliance
The Internet-facing VPN appliance is the highest priority because it is directly exposed to untrusted networks (the Internet), making it the most likely entry point for attackers. A compromise here could lead to full network access, bypassing all other security controls, which represents the greatest real-world risk regardless of its severity score.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Internet-facing VPN appliance
Why this is correct
This asset should be remediated first because it is directly reachable from the internet, has a publicly known exploit that can be weaponized without authentication, and currently lacks compensating controls such as a WAF, access-control list, or host IPS. That combination yields the highest probability of successful remote compromise in the shortest time, so even if other assets have higher raw CVSS scores, the VPN appliance presents the greatest immediate risk to the organization.
- ✗
Internal HR file server
Why it's wrong here
The HR file server may have a high risk score due to sensitive data and the potential for lateral movement, but it is not directly internet-exposed and is protected by layered controls such as network segmentation, host firewall rules, authentication requirements, and EDR. An attacker must first breach another system or gain valid credentials to reach it, which significantly lowers the likelihood of immediate exploitation compared with an internet-facing device with a known exploit. Therefore, it should not be prioritized above the VPN appliance.
- ✗
Lab workstation
Why it's wrong here
The lab workstation is isolated from production and likely has no internet exposure or access to critical systems, making the business impact of a compromise mostly limited to research or test data. Even if the vulnerability is severe, the attack surface and blast radius are constrained by network isolation, so the probability of an attacker reaching it from the internet is low. Remediation can be deferred while the internet-facing VPN appliance remains an active entry point.
- ✗
DMZ reporting server
Why it's wrong here
The DMZ reporting server is externally reachable, but it sits behind a web application firewall and an IP allowlist, which means an attacker must first evade those controls or already be on an allowed source before the vulnerability can be exploited. Those compensating controls materially lower the practical exploitability of the vulnerability, unlike the VPN appliance that has no such mitigations. Once the VPN appliance is secured, this server should still be patched, but it is not the first priority.
Go deeper
Related to this question
Learn chapter
Network-Based Attacks
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Based on the exhibit, which finding should be remediated first?
hard- ✓ A.Finding A
- B.Finding B
- C.Finding C
- D.Finding D
Why A: Finding A is prioritized first because it represents the highest overall risk when considering exploitability, potential impact, and asset criticality. While CVSS scores are a factor, remediation decisions should weigh the likelihood of exploitation and the severity of consequences; Finding A poses an immediate and severe threat that could lead to significant compromise, thereby requiring urgent action.
Variation 2. Based on the exhibit, which finding should the security team remediate first?
easy- A.LAP09 because user devices are always the easiest to patch
- ✓ B.WEB01 because it is internet-facing and has a critical exploitable vulnerability
- C.PRN01 because firmware issues can affect many users
- D.FILE02 because internal servers are always more important than public ones
Why B: WEB01 is internet-facing and has a critical exploitable vulnerability, meaning an attacker can directly compromise it from the public internet with minimal effort. This represents the highest risk because it combines high likelihood (exploit available) with high impact (full compromise of a public-facing server). Remediating this first aligns with the principle of prioritizing externally exposed systems with known critical flaws over internal or less severe issues.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.