Courseiva

SSCP Security Operations and Administration Practice Question

A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?

⚠ Common exam trap

SSCP often tests the distinction between technical severity (CVSS) and business impact (asset criticality), tricking candidates into choosing operational metrics like patch size or cost that feel practical but are not risk-based prioritization factors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CVSS score and asset criticality

CVSS score quantifies the technical severity of a vulnerability (base, temporal, and environmental metrics), while asset criticality reflects the business impact if that asset is compromised. Combining these two factors ensures patches that are both highly exploitable and protect the most valuable systems are applied first, which is the standard risk-based prioritization approach in patch management frameworks like those from NIST and CIS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CVSS score and asset criticality

    Why this is correct

    CVSS score quantifies technical severity, while asset criticality reflects business impact if that host is compromised. Combining both prevents wasting effort on severe flaws on trivial systems and ensures patches for exploitable vulnerabilities on high-value assets are applied first.

  • ✗

    Number of systems affected and patch size

    Why it's wrong here

    Patch size is irrelevant to risk, and system count alone ignores severity; a critical remote-code-execution flaw on one internet-facing server outranks a cosmetic fix on a thousand workstations. Severity plus exposure and asset criticality determine the order patches should be applied.

  • ✗

    Age of the patch and vendor reputation

    Why it's wrong here

    Patch age and vendor reputation say nothing about exploitability or exposure; an old patch for unused software outranks a fresh critical remote-code-execution fix under this logic. Reputation is also subjective. Severity combined with internet exposure and asset criticality drives prioritisation instead.

  • ✗

    Cost of the patch and availability of workarounds

    Why it's wrong here

    Patch priority hinges on exploitability and severity, not procurement cost or workaround availability. Cost and workarounds inform risk acceptance or deferral decisions once a vulnerability's CVSS rating and exposure are known, so they belong to remediation planning rather than the initial prioritisation ranking itself.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.