SSCP Security Operations and Administration Practice Question
A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?
⚠ Common exam trap
SSCP often tests the distinction between technical severity (CVSS) and business impact (asset criticality), tricking candidates into choosing operational metrics like patch size or cost that feel practical but are not risk-based prioritization factors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CVSS score and asset criticality
CVSS score quantifies the technical severity of a vulnerability (base, temporal, and environmental metrics), while asset criticality reflects the business impact if that asset is compromised. Combining these two factors ensures patches that are both highly exploitable and protect the most valuable systems are applied first, which is the standard risk-based prioritization approach in patch management frameworks like those from NIST and CIS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CVSS score and asset criticality
Why this is correct
CVSS score quantifies technical severity, while asset criticality reflects business impact if that host is compromised. Combining both prevents wasting effort on severe flaws on trivial systems and ensures patches for exploitable vulnerabilities on high-value assets are applied first.
- ✗
Number of systems affected and patch size
Why it's wrong here
Patch size is irrelevant to risk, and system count alone ignores severity; a critical remote-code-execution flaw on one internet-facing server outranks a cosmetic fix on a thousand workstations. Severity plus exposure and asset criticality determine the order patches should be applied.
- ✗
Age of the patch and vendor reputation
Why it's wrong here
Patch age and vendor reputation say nothing about exploitability or exposure; an old patch for unused software outranks a fresh critical remote-code-execution fix under this logic. Reputation is also subjective. Severity combined with internet exposure and asset criticality drives prioritisation instead.
- ✗
Cost of the patch and availability of workarounds
Why it's wrong here
Patch priority hinges on exploitability and severity, not procurement cost or workaround availability. Cost and workarounds inform risk acceptance or deferral decisions once a vulnerability's CVSS rating and exposure are known, so they belong to remediation planning rather than the initial prioritisation ranking itself.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.