nerdexam
CompTIA

CAS-005 · Question #305

A security engineer is reviewing the following vulnerability scan report: Which of the following should the engineer prioritize for remediation?

The correct answer is B. OpenSSH. While the Apache vulnerability has the highest CVSS score (9.7), the OpenSSH vulnerability (CVSS 9.2) is on a public-facing system, making it more immediately exploitable from external sources. Prioritizing public-facing, high-severity vulnerabilities is critical to reducing…

Submitted by hans_de· Mar 6, 2026Security Operations

Question

A security engineer is reviewing the following vulnerability scan report:

Which of the following should the engineer prioritize for remediation?

Exhibits

CAS-005 question #305 exhibit 1
CAS-005 question #305 exhibit 2

Options

  • AApache HTTP Server
  • BOpenSSH
  • CGoogle Chrome
  • DMigration to TLS 1.3

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    82% (18)
  • C
    5% (1)
  • D
    5% (1)

Explanation

While the Apache vulnerability has the highest CVSS score (9.7), the OpenSSH vulnerability (CVSS 9.2) is on a public-facing system, making it more immediately exploitable from external sources. Prioritizing public-facing, high-severity vulnerabilities is critical to reducing exposure.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice