Triage BoardGet the app

Domain 2 · Vulnerability Management

Prioritizing and mitigating vulnerabilities

Prioritizing vulnerabilities means deciding which findings to fix first and how to mitigate the rest, and objective 2.3 hands you exactly that pile. The base score alone never settles it: CS0-004 weighs exploitability, active exploitation, asset value, impact, patch availability and whether the finding is real, alongside two scoring systems that measure different things, CVSS and EPSS.

  • Exam code CS0-004
  • Domain weight 26%
  • Tickets here 16

Your 2.3 worklist

  • Weigh each finding on the listed criteria: exploitability, active exploitation and threat intelligence, asset value, impact, patch or remediation availability, true or false positives and negatives
  • Read CVSS metrics and an EPSS probability, and keep the two meanings apart
  • Adjust for context: internal, external or isolated
  • Pick a mitigation: attack surface management, secure coding, patching and configuration management, an exception, or a compensating control
  • Validate that the remediation worked

The criteria, one at a time

Exploitability. How easy the flaw is to use: reachable over the network, no privileges needed, no user interaction, public exploit code. The Common Vulnerability Scoring System (CVSS) captures most of this in its base metrics.

Active exploitation and threat intelligence. Evidence that attackers use the flaw now. The common signal is a listing in CISA's Known Exploited Vulnerabilities (KEV) catalog. Intelligence feeds add which campaigns and sectors are involved.

Asset value and impact. What the host does and what it holds. The same flaw on a domain controller and on a lobby kiosk belongs in two different queues.

Patch or remediation availability. When no fix exists, the work moves from patching to an exception backed by a compensating control.

True or false, positive or negative. A finding nobody has confirmed may not exist, and a clean report can hide a real flaw the scanner never saw.

Scoring. CVSS rates severity from 0.0 to 10.0, in bands shared by v3.1 and v4.0: None 0.0, Low 0.1–3.9, Medium 4.0–6.9, High 7.0–8.9, Critical 9.0–10.0 (FIRST CVSS v4.0 specification, checked October 2026). The Exploit Prediction Scoring System (EPSS) gives a probability from 0 to 1 that a CVE will be exploited in the wild in the next 30 days (FIRST EPSS, checked October 2026). One measures how bad a flaw is and the other how likely it is to be used, which is the subject of CVSS vs EPSS. Reading a v4.0 vector, with its Threat group in place of v3.1's Temporal, is covered in CVSS 4.0 vs 3.1.

Context. External means anyone on the internet can reach it. Internal needs a foothold first. Isolated (air-gapped or cut off by segmentation) lowers the likelihood without erasing it.

Exposure against severity

Low or MediumHighCriticalExternalNormal cycleExpediteFix firstInternalBacklogNormal cycleExpediteIsolatedBacklogBacklogNormal cycle
An illustrative starting order before exploitation evidence and asset value move a cell. A KEV listing pushes a finding up from wherever it starts.

Ranking four findings

Fictional findings with placeholder CVE ids: the order and why
FindingCVSS v4.0EPSSContextRank and reason
CVE-20XX-0101, file-transfer gateway9.3 Critical0.89External; listed in KEV; vendor patch out1: reachable, exploited now, and the fix is ready
CVE-20XX-0102, payroll database8.7 High0.02Internal; holds payroll data2: high-value data one foothold away
CVE-20XX-0103, lab build server9.2 Critical0.40Isolated lab segment3: severe, but reachable only from the lab
CVE-20XX-0104, print server5.3 Medium0.01Internal; vendor patch out4: next normal patch cycle

Neither column of scores produces this order alone. The ranking comes from reading score, probability, exposure and asset value together.

From decision to closed ticket

  1. Choose the mitigation

    Patch or reconfigure when a fix exists. Shrink what is exposed by retiring unused services and closing ports. When the flaw is in your own code, fix it with secure coding practice; the OWASP Top 10:2025 puts Broken Access Control at A01. Catching such flaws before release is the job of SAST, DAST and SCA.

  2. If you cannot fix it yet, document an exception

    Record an owner, a reason and an expiry date, plus the compensating control that carries the risk in the meantime. Who may approve an exception is a policy question, covered in controls, risk and the vulnerability program.

  3. Apply the change through change management

    Patching is planned work. NIST SP 800-40r4 frames patching as preventive maintenance: tested, scheduled and reversible.

  4. Validate

    Rescan with the same profile and credentials as the original scan, so a clean result means fixed and not just unexamined. A ticket closes only after validation.

A compensating control is not a fixTrap

An exception plus a compensating control (segmentation, a web application firewall rule, extra monitoring) lowers the risk while the vulnerability stays in place. The finding stays open with an owner and an expiry date, and the control itself needs testing. An option that closes the finding because the control went in is wrong for that reason.

Triage the findings

Rank the findings in every exhibit on the criteria above, then pick.

Ticket 1 / 16

0 right

INC-001

An organization typically follows a 30-day vendor patch cycle. Active exploitation campaigns currently target VPN appliances. Which prioritization inputs justify overriding the default cycle?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Internet-facing exposure plus public exploits under active attack put the VPN appliances at real risk now, so emergency patching ahead of the 30-day cycle is justified.
  2. BBaseline requirements and the routine patch cycle are the default process being overridden, so they can't be the reason to override it.
  3. CIsolated development systems are the opposite of the exposed VPN edge, and their criticality says nothing about the active campaign.
  4. DA high CVSS base score with a normal vendor timeline describes severity only; without exposure and active exploitation it doesn't justify breaking the cycle.

INC-002

An analyst is reviewing a vulnerability scan report. Following CISA guidance, which host requires the most immediate prioritization, and what action should be taken since a direct patch is currently unavailable?

Exhibit

HostExposureCVSS v3.1 baseCISA KEV ListedPatch Available
Dev-DBInternal9.8NoYes
Prod-WebInternet-facing7.4YesNo
Prod-AppInternal8.1NoYes
Dev-TestInternet-facing6.5NoYes

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AProd-App is internal, not KEV-listed, and has a patch, so it is not the most urgent, and isolating it until a maintenance window is not the answer.
  2. BDev-Test is internet-facing but not KEV-listed and has a patch, so it can follow the normal cycle.
  3. CCorrect: Prod-Web is internet-facing and listed in CISA's Known Exploited Vulnerabilities catalog, so it comes first; with no patch available, apply compensating controls (such as a WAF rule, access restriction or disabling the affected feature) now.
  4. DDev-DB has the highest CVSS score (9.8) but is internal, not known to be exploited and patchable, so a high score alone doesn't make it most urgent.

INC-003

A private, tightly segmented internal database service has a high-severity vulnerability, while an internet-facing workload with administrative privileges has a medium-severity vulnerability. Why might the medium-severity vulnerability be prioritized?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe medium flaw sits on the internet-facing workload while this answer targets the internal database, so it gets the target wrong.
  2. BBeing outside the compliance scope wouldn't raise its priority, and the stem says nothing about compliance boundaries.
  3. CNothing in the stem says the software can't be patched, and being unpatchable wouldn't explain why exposure drives priority.
  4. DCorrect: Exposure to the internet and administrative privileges make a medium flaw easier to reach and more damaging than a high flaw on a tightly segmented internal service.

INC-004

An attacker can reach a high-value database by pivoting through three web servers. Which remediation plan reduces attacker reachability with the fewest fixes?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: If all three paths pass through one chokepoint, hardening that single point cuts the attacker off from the database with the least work.
  2. BFixing the lowest-CVSS findings first leaves the actual path to the database open and does nothing to reduce reachability.
  3. CPatching every web server vulnerability works, but it is the most fixes instead of the fewest.
  4. DDisabling all external access removes reachability by breaking the business, which is not a remediation plan.

INC-005

An analyst recommends shutting down production clusters based purely on a massive influx of static container vulnerabilities. What fundamental error is the analyst making in their risk evaluation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ASignature updates affect what the scanner detects; they don't change the fact that a static scan is not the same as what is actually exposed at runtime.
  2. BRegistries don't patch images automatically, but this belief isn't the error in recommending a shutdown based on scan counts.
  3. CCorrect: An image scan lists vulnerable packages without measuring exposure; whether those packages are loaded, reachable or covered by runtime controls decides the real risk.
  4. DScanning overhead is a performance concern and not the flaw in a decision to shut down production.

INC-006

Regulatory requirements mandate 14-day patching for high-data-classification systems. A KEV-listed RCE affects one such system. Which remediation order is most defensible?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: A known exploited RCE on a system that falls under the 14-day regulatory rule goes first, both because of active exploitation and the compliance deadline.
  2. BStarting with the lowest-CVSS items leaves the most dangerous, exploited flaw open longest.
  3. CPatching non-regulated systems first delays the asset that has both active exploitation and a regulatory deadline.
  4. DGiving every asset the same priority ignores exploitation, data classification and the regulatory deadline.

INC-007

Given scanner data showing CVSS, exploit evidence, asset value, and compensating control status, which remediation prioritization approach is correct?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA compensating control lowers risk but does not remove it, and deferring every item that has one can leave exploited flaws open indefinitely.
  2. BCorrect: Combine CVSS with exploit evidence, asset value, exposure and compensating controls, then put findings into SLA buckets so that each one has a deadline.
  3. CPutting isolated assets first regardless of exploitation flips the logic, because exposure and active exploitation should raise priority.
  4. DA uniform 30-day deadline ignores the context the scanner data gives you, so critical exploited items wait as long as trivial ones.

INC-008

An asset previously classified as low criticality is reclassified as containing regulated data. How should its vulnerabilities be reprioritized?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ARegulated data raises the impact of a compromise, so lowering priority goes the wrong way.
  2. BKeeping the old schedule ignores that the asset's value and regulatory impact have changed.
  3. CRemoving a regulated-data asset from scans creates a blind spot and would likely breach compliance requirements.
  4. DCorrect: Holding regulated data raises the asset's criticality, so its vulnerabilities should get higher priority and shorter remediation deadlines.

INC-009

What is the primary purpose of vulnerability validation in a vulnerability management program?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ACompliance documentation may use validated results, but it is not why you validate findings.
  2. BAn overall security score is a reporting metric and is separate from checking whether individual findings are real.
  3. CCorrect: Validation checks whether a finding is real and exploitable in your environment, which removes false positives and focuses effort on actual risk.
  4. DAssigning work to system owners is remediation workflow that comes after validation and prioritization.

INC-010

After patching web servers, a rescan shows the vulnerability is absent but latency and error rates have increased. Which validation must occur before closing the ticket?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Close only after the rescan confirms the fix and a defined monitoring period shows latency and error rates back within agreed thresholds.
  2. BChecking that transactions succeed without latency thresholds ignores the performance degradation the patch has already caused.
  3. CAutomated configuration checks confirm settings but cannot show that the service is performing normally after the patch.
  4. DClosing on a clean rescan alone ignores the new latency and errors, so a security fix that broke service would go unnoticed.

INC-011

Design the correct sequence for a four-stage critical OS patch rollout across mixed hardware environments.

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ARolling straight into production with no lab or pilot testing risks outages across mixed hardware, and snapshots don't replace testing.
  2. BA pilot on identical hardware misses problems on the other models in a mixed fleet, and jumping straight to a full rollout gives no staged checkpoints.
  3. CCorrect: Test in a lab, pilot on a representative mix of hardware, widen in growing cohorts and then roll out fully, with rollback checkpoints at each stage.
  4. DValidating in the lab after a full production deployment gets the order backwards, because issues are found only after they hit every system.

INC-012

A critical internet-facing server has an unauthenticated RCE. Which element must be included in the remediation ticket?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AA business impact statement explains why the fix matters, but on its own it gives the implementer nothing to act on.
  2. BA CVE ID and CVSS score identify the flaw but don't say how to fix it safely or when.
  3. CA patch link without version data doesn't tell the implementer which versions are affected or what to install.
  4. DCorrect: A change on a critical production server needs a rollback plan and a maintenance (or emergency change) window so the fix can be applied safely and undone if it breaks something.

INC-013

A system administrator attempted to remediate a high-severity vulnerability within a running application container by installing an updated software package directly via an interactive shell. Why is this remediation approach incorrect?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AChanges inside a container don't corrupt the host OS; the problem is that the fix doesn't last.
  2. BCorrect: Containers are meant to be immutable, so a package installed in a running container disappears when it is replaced; fix the image, rebuild and redeploy it.
  3. COrchestrators don't roll back manual changes; they replace containers from the original image on restart, which quietly undoes the fix.
  4. DThe fix belongs in the image build, but the shell approach is wrong because of the immutability principle, and no rule requires updating CI at the same time.

INC-014

A web application outputs user input in HTML, attribute, and JavaScript contexts. Which mitigation strategy correctly addresses reflected XSS across these contexts?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AOne regex applied before storage can't cover every output context, and regex-based XSS filters are easy to bypass.
  2. BRejecting special characters everywhere breaks legitimate input and still misses context-specific payloads, because XSS is fixed by encoding at output.
  3. CEncoding only for HTML leaves attribute and JavaScript contexts open, and browsers don't encode output for you.
  4. DCorrect: Encode output for each context it goes into (HTML body, attribute, JavaScript), and add a Content Security Policy as a second layer.

INC-015

Which of the following attacks exploits unvalidated user inputs to a web application in order to execute commands on the server?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AA buffer overflow writes past the end of a memory buffer, a memory-safety flaw that has nothing to do with using input to run server commands.
  2. BAn on-path (man-in-the-middle) attack intercepts traffic between two parties and does not rely on unvalidated input to the application.
  3. CCross-site scripting injects script that runs in the victim's browser instead of commands on the server.
  4. DCorrect: command injection passes unvalidated input to a system shell or command, so the server runs commands the attacker chose.

INC-016

What is the BEST way to handle vulnerability management for shadow IT resources discovered during a scan?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ADisciplinary reports don't reduce the vulnerability risk and push shadow IT further out of sight.
  2. BCorrect: Bring the assets into the inventory, assess their risk, then decide whether to integrate them into normal management or decommission them.
  3. CShutting everything down at once can break business processes that depend on these resources, without any risk assessment.
  4. DIgnoring them leaves unmanaged, unpatched systems on the network, which is exactly why shadow IT is a risk.

Shift tally

0 / 0

Four rules for the queue

  • CVSS measures severity. EPSS estimates the chance of exploitation in the next 30 days. Use both.
  • Exposure and evidence of active exploitation can lift a finding above one with a higher base score.
  • No patch means an exception plus a compensating control, with an expiry date.
  • A finding counts as closed only after a rescan with the original settings.

Sources

  1. FIRST, CVSS v4.0 specification · metric groups and severity bands (checked October 9, 2026)
  2. FIRST, Exploit Prediction Scoring System (EPSS) · 30-day exploitation probability (checked October 9, 2026)
  3. CISA, Known Exploited Vulnerabilities catalog (checked October 9, 2026)
  4. NIST, SP 800-40r4 Guide to Enterprise Patch Management Planning (checked October 9, 2026)
  5. CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) · objective 2.3 (checked October 9, 2026)

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.