Triage BoardGet the app

Concept · Prioritization and mitigation

CVSS vs EPSS: severity vs likelihood

The Common Vulnerability Scoring System (CVSS) rates how severe a vulnerability is on a 0–10 scale; the Exploit Prediction Scoring System (EPSS) estimates the probability, from 0 to 1, that it will be exploited in the wild in the next 30 days (FIRST, checked October 2026). They answer different questions, and objective 2.3 of the CS0-004 exam expects you to weigh them together with known exploitation, exposure and asset value when you prioritize vulnerabilities.

  • Exam code CS0-004
  • Tickets here 8

Severity score, likelihood score

What each score tells you, per FIRST (checked October 2026)
PointCVSSEPSS
Question it answers≠How bad is it if someone exploits it?How likely is exploitation soon?
Output≠A 0.0–10.0 score and a vector stringA probability from 0 to 1, with a percentile
Time window≠None in the Base scoreThe next 30 days
Uses your environment≠Only through the Environmental metrics you fill inNo: the same number for every organization
How it moves≠Base stays put; v4.0 Threat metrics adjust for exploit maturityRe-estimated as exploitation data changes
Maintained byFIRST (Forum of Incident Response and Security Teams)FIRST (Forum of Incident Response and Security Teams)

Rows marked ≠ are where the two differ.

Two axes, four queues

Lower CVSSHigher CVSSHigh EPSSPatch soon;check exposurePatch firstLow EPSSNormal cyclePatch; watchEPSS
A rough sorting grid. A KEV listing, internet exposure or a high-value asset can move any cell up a queue.

Every signal and what it adds

The inputs objective 2.3 lists for prioritizing, with where each one comes from
SignalWhat it addsWhere it comes from
CVSS BaseWorst-case severity of the flaw itselfVendor or database score
CVSS EnvironmentalSeverity adjusted to your asset and its controlsYour own team
EPSSChance of exploitation in the next 30 daysFIRST model
Known exploitationEvidence attackers already use itThreat intel; CISA KEV catalog
ExposureInternet-facing, internal or isolatedNetwork context, asset inventory
Asset valueWhat the business loses if this host fallsAsset owner, data classification
Patch availabilityWhether a fix exists yetVendor advisory

Patch availability decides what you do next: patch, or put a compensating control in place until you can.

How CySA+ builds these questions

Prioritization items usually put several findings in front of you with a mix of scores and context, and at least one option ranks them by the biggest CVSS number alone. Before you look at the options, write three words next to each finding: exploited, exposed, valuable. Each yes moves a finding up the queue. Scores then settle the order among findings that tie on those three.

EPSS also comes with a percentile, which tells you how a CVE's probability ranks against every other scored CVE (FIRST, checked October 2026). A probability that looks small can still rank high against the rest, so read which of the two numbers the stem gives you.

EPSS is not a severity ratingTrap

A low EPSS value means low likelihood of exploitation in the next 30 days. It says nothing about impact, and it can change as attackers change targets. Options that turn an EPSS value into a High, Medium or Low severity label, or that treat a low EPSS as permission to ignore a flaw, misread the score.

Rank the queue

Decide what you would fix first with everything the ticket gives you: the severity score, the exploitation data and what the asset does.

Ticket 1 / 8

0 right

INC-001

Two vulnerabilities have identical CVSS 9.0 scores. One has EPSS 0.85 and published PoC code; the other has EPSS 0.12 and no PoC. Which should be escalated first?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: with equal CVSS scores, an EPSS of 0.85 plus public proof-of-concept code means exploitation is far more likely soon, so it goes first.
  2. BPlugin IDs are arbitrary scanner identifiers and say nothing about risk.
  3. CConfirming exposure matters, but it should not stall escalation of an item with strong exploitation signals.
  4. DEPSS 0.12 with no public exploit means this item is less likely to be exploited soon, so it comes second.

INC-002

What is the most effective operational sequence for triaging a newly disclosed vulnerability that is suspected of active exploitation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AFiling an exception and waiting for the vendor is too passive for a vulnerability that may already be exploited.
  2. BMass quarantines and blocking all ingress before confirming exposure are disruptive and come in the wrong order.
  3. CImaging every endpoint is incident response, not vulnerability triage, and patching before assessing exposure skips prioritization.
  4. DCorrect: confirm exploitation signals in threat feeds and EPSS, check which assets are actually exposed, then assess available fixes or mitigations.

INC-003

A KEV-listed vulnerability with CVSS 6.5 exists on a high-value asset while a CVSS 9.1 finding exists on an isolated test system. Which prioritization is correct?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA known-exploited flaw on a high-value asset carries more real risk than a higher score on an isolated test box, so equal priority is wrong.
  2. BCorrect: listing in CISA's Known Exploited Vulnerabilities (KEV) catalog proves real-world exploitation, and on a high-value asset that outweighs a higher CVSS score.
  3. CThe 9.1 sits on an isolated test system, so its exposure and business impact are low despite the score.
  4. DDeferring a known-exploited vulnerability on a high-value asset leaves the most likely attack path open.

INC-004

An organization suffered a breach via CVE-B despite patching all vulnerabilities with CVSS scores above 9.0. Based on the table, why did prioritizing CVE-A over CVE-B result in a breach?

Exhibit

CVECVSS ScoreAttack VectorKEV StatusAsset Exposure
CVE-A9.8NetworkNot ListedInternal Database
CVE-B7.2NetworkActively ExploitedInternet-Facing Web

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe table shows nothing about authentication requirements, and CVE-B was actively exploited, so it was clearly exploitable.
  2. BCVE-A's higher score is exactly why it was patched first, and that score-only logic is what caused the breach.
  3. CCVE-B is a documented CVE listed as actively exploited, so it was not an undocumented zero-day.
  4. DCorrect: patching by score alone ignored that CVE-B was internet-facing and actively exploited, making it the real risk.

INC-005

What is the primary limitation of using only CVSS Base Scores for vulnerability prioritization?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ABase scores combine exploitability and impact metrics, so they measure more than exploitability.
  2. BBase scores are meant to stay stable for a vulnerability; Threat (v4.0) or Temporal (v3.1) metrics are the ones that change over time.
  3. CCorrect: base scores describe the vulnerability in general, not your asset value, exposure, compensating controls or threat activity, which is why Environmental and Threat metrics exist.
  4. DCVSS is widely used and documented, so complexity is not its main limitation.

INC-006

A scanner reports CVSS 9.8 remote code execution on a low-value internal dev host and CVSS 6.5 privilege escalation on an internet-facing production database. Which remediation priority is correct?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe dev host is described as low value, so this reverses the actual asset priority.
  2. BTreating both the same ignores exposure and asset value, which should set the order.
  3. CRanking by CVSS alone ignores that the 9.8 sits on a low-value internal host.
  4. DCorrect: an internet-facing production database has higher exposure and value, so its 6.5 flaw is the bigger real risk.

INC-007

Based on the integrated vulnerability and threat intelligence dashboard, which internal vulnerability requires immediate emergency prioritization due to a sudden escalation in exploitability metrics?

Exhibit

Internal IDCVSSOriginal EPSSUpdated EPSS
VULN-019.80.050.06
VULN-027.50.020.89
VULN-038.10.150.15
VULN-049.00.100.12

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AVULN-01 has the highest CVSS, but its EPSS barely moved (0.05 to 0.06), so its exploitation likelihood did not change.
  2. BVULN-03's EPSS stayed at 0.15, so nothing escalated.
  3. CCorrect: VULN-02's EPSS jumped from 0.02 to 0.89, meaning exploitation in the next 30 days is now very likely, which justifies emergency reprioritization.
  4. DVULN-04's EPSS rose only slightly (0.10 to 0.12), and its high CVSS reflects severity without any change in exploitability.

INC-008

Scanner results include exploit maturity data. How should prioritization be adjusted?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AEqual urgency for every finding wastes effort on low-risk items and delays the dangerous ones.
  2. BCVSS alone measures severity and says nothing about whether exploits exist or how exposed the asset is.
  3. CPublic exploit data is a key signal of real-world risk, so ignoring it misses active threats.
  4. DCorrect: combining CVSS with exploit maturity, exposure, asset value and SLA requirements produces a risk-based remediation order.

Shift tally

0 / 0

When the scores disagree

Can I use EPSS instead of CVSS?

No. EPSS estimates likelihood and CVSS describes severity. A sensible queue uses both, then adds what only you know: exposure, asset value and the controls already in place.

What do I need to know about the KEV catalog?

CISA's Known Exploited Vulnerabilities catalog lists CVEs with evidence of exploitation in the wild (cisa.gov, checked October 2026). On the exam it is the clearest example of the "active exploitation" criterion in objective 2.3.

Which CVSS version should I learn for CS0-004?

The CS0-004 objectives say "CVSS metrics" without naming a version (version 2.0 of the objectives, checked October 2026). Learn to read both; the CVSS v4.0 vs v3.1 guide walks through the vector changes.

What do I do when a high-priority flaw can't be patched yet?

You document an exception and add a compensating control that blocks the same attack path until the fix lands.

Sources

  1. FIRST, Exploit Prediction Scoring System (EPSS) (checked October 9, 2026)
  2. FIRST, CVSS v4.0 specification (checked October 9, 2026)
  3. CISA, Known Exploited Vulnerabilities catalog (checked October 9, 2026)
  4. CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) · objective 2.3 (checked October 9, 2026)

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.