Courseiva
mediumMultiple Select

CISSP Vulnerability Prioritization Practice Question

A security analyst is reviewing the findings from a vulnerability scan of a web application. Which TWO actions are most appropriate to prioritize remediation?

⚠ Common exam trap

Candidates often think only one of these factors is sufficient. However, CISSP emphasizes that remediation priority should consider both exploitability (known exploit existence) and severity (CVSS score) together. A high CVSS vulnerability without an exploit may be less urgent than one with a known exploit, but both are important inputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Whether a known exploit exists

Option C is correct because the existence of a known, weaponized exploit (e.g., one listed in CISA's KEV catalog or available in Metasploit) dramatically raises the likelihood of active compromise, so it should drive remediation priority. Option E is correct because the CVSS score provides a standardized, quantitative measure of a vulnerability's severity (base, temporal, and environmental metrics), making it a primary input for ranking remediation efforts. Options A, B, and D are not the best answers here: asset value is a contextual factor that can influence prioritization but is not itself a vulnerability attribute used to rank scan findings, the number of times a scan was run is irrelevant to the severity of a finding, and the discovery date does not indicate exploitability or impact, though age may matter for SLA tracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The asset's value to the organization

    Why it's wrong here

    While the asset's value is an important factor in overall risk management, the question specifically asks for actions most appropriate to prioritize remediation based on vulnerability scan findings. Asset value is not a direct output of the scan; thus it is not among the best two choices here.

  • ✗

    The number of times the scan was run

    Why it's wrong here

    The number of times the scan was run does not indicate the severity or exploitability of a vulnerability. It is irrelevant for prioritization.

  • ✓

    Whether a known exploit exists

    Why this is correct

    Correct. Whether a known exploit exists is a key factor because vulnerabilities with existing exploits are more likely to be targeted, increasing urgency.

  • ✗

    The date the vulnerability was discovered

    Why it's wrong here

    The date the vulnerability was discovered is less relevant than severity and exploitability. Older vulnerabilities may have been patched, while newer ones might not have exploits yet.

  • ✓

    The CVSS score of the vulnerability

    Why this is correct

    Correct. The CVSS score provides a standardized severity metric, helping to prioritize vulnerabilities with higher potential impact.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.