Courseiva
Vulnerability Scanning →mediumMultiple Select

GPEN Vulnerability Scanning Practice Question

A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)

⚠ Common exam trap

The trap here is overemphasizing technical metrics like CVSS without considering business context, or vice versa, leading to misprioritization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The potential impact on the business if exploited

CVSS base score and business impact are key factors for prioritizing vulnerabilities. CVSS provides a standardized severity metric, while business impact ensures that remediation efforts focus on what matters most to the organization. Together, they help balance technical severity with real-world consequences.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The potential impact on the business if exploited

    Why this is correct

    Business impact is crucial because a vulnerability with a moderate CVSS score might be critical if it affects a key asset or sensitive data. Understanding the business context helps prioritize remediation that aligns with organizational risk appetite and compliance requirements.

  • ✗

    The age of the vulnerability in the CVE database

    Why it's wrong here

    The age of a CVE does not determine its current criticality. Older vulnerabilities may still be actively exploited if patches are not applied. Prioritization should be based on current exploitability and impact, not the date of disclosure.

  • ✓

    The CVSS base score of the vulnerability

    Why this is correct

    The CVSS base score provides a standardized severity rating based on intrinsic characteristics like attack vector and impact. It helps compare vulnerabilities objectively. However, it does not account for the specific environment, so it should be used in conjunction with other factors.

  • ✗

    The number of other vulnerabilities on the same host

    Why it's wrong here

    The quantity of vulnerabilities on a host does not directly indicate the criticality of a specific vulnerability. A single critical flaw is more urgent than many low-severity issues. Focusing on count can lead to misprioritization and neglect of the most dangerous findings.

  • ✗

    The scanner's confidence level in the finding

    Why it's wrong here

    While confidence level can affect whether a finding is a false positive, it is not a primary factor for criticality. Once a vulnerability is confirmed, criticality is based on severity and impact. Confidence helps validate findings but does not change the inherent risk.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.