nerdexam
Cisco

350-201 · Question #110

Refer to the exhibit. Based on the detected vulnerabilities, what is the next recommended mitigation step?

The correct answer is C. Remediate all vulnerabilities with descending CVSS score order. When multiple vulnerabilities are detected, they should be remediated in order of descending CVSS score to address the most critical risks first.

Techniques

Question

Refer to the exhibit. Based on the detected vulnerabilities, what is the next recommended mitigation step?

Exhibit

350-201 question #110 exhibit

Options

  • AEvaluate service disruption and associated risk before prioritizing patches.
  • BPerform root cause analysis for all detected vulnerabilities.
  • CRemediate all vulnerabilities with descending CVSS score order.
  • DTemporarily shut down unnecessary services until patch deployment ends.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    10% (4)
  • C
    83% (33)
  • D
    5% (2)

Why each option

When multiple vulnerabilities are detected, they should be remediated in order of descending CVSS score to address the most critical risks first.

AEvaluate service disruption and associated risk before prioritizing patches.

Evaluating service disruption before prioritizing is a secondary consideration - CVSS scores already factor in exploitability and impact, providing a ready-made prioritization framework that should be applied directly.

BPerform root cause analysis for all detected vulnerabilities.

Root cause analysis is a post-incident or post-remediation activity and is not the immediate mitigation step when vulnerabilities have been detected and need to be addressed.

CRemediate all vulnerabilities with descending CVSS score order.Correct

CVSS (Common Vulnerability Scoring System) scores provide a standardized numeric severity rating that allows security teams to prioritize remediation effectively. Addressing vulnerabilities in descending CVSS score order ensures the most critical and exploitable vulnerabilities are patched first, reducing overall organizational risk in a structured manner. This is the industry-standard approach endorsed by NIST and FIRST for vulnerability management programs.

DTemporarily shut down unnecessary services until patch deployment ends.

Temporarily shutting down services causes unnecessary business disruption and is not the recommended standard approach for patch deployment prioritization when CVSS scoring already guides sequencing.

Concept tested: Vulnerability prioritization using CVSS scoring

Source: https://www.first.org/cvss/

Topics

#CVSS scoring#vulnerability prioritization#patch management#remediation

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice