Courseiva
Risk Identification, Monitoring, and AnalysishardMultiple ChoiceObjective-mapped

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A vulnerability scan identifies a critical vulnerability with a CVSS score of 9.8. According to standard remediation SLAs, within what timeframe should this vulnerability typically be remediated?

⚠ Common exam trap

Candidates often confuse the CVSS severity categories with the typical SLA timeframes, often assuming that all 'critical' vulnerabilities have a 7-day window, when in fact the most severe (9.0–10.0) require remediation within 24–72 hours per standard industry frameworks like PCI DSS or NIST.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

24-72 hours

A CVSS score of 9.8 falls into the 'Critical' severity range (9.0–10.0). Standard remediation SLAs for critical vulnerabilities typically require action within 24–72 hours because such vulnerabilities often allow remote code execution or complete compromise without authentication, posing an immediate and severe risk to the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 30 days

    Why it's wrong here

    This is typical for high vulnerabilities.

  • 24-72 hours

    Why this is correct

    Critical vulnerabilities require immediate attention.

  • 7 days

    Why it's wrong here

    This is more typical for high vulnerabilities.

  • 90 days

    Why it's wrong here

    This is typical for medium vulnerabilities.

About these practice questions

This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.