nerdexam
CompTIA

CAS-005 · Question #497

A security team is evaluating the following vulnerabilities in response to a third-party risk assessment: Given the following organizational policy requirements: - Any adjusted CVSS score of 7.0 or gr

The correct answer is A. Implement a patch for CVE-2025-1234.. CVE-2025-1234 has an adjusted CVSS score of 7.1, which meets the policy requirement for remediation within 15 days. The other vulnerabilities (5.6 and 6.9) fall below the 7.0 threshold and can be remediated within 30 days, so the immediate action is to implement a patch for CVE-

Submitted by alyssa_d· Mar 6, 2026Governance, Risk, and Compliance

Question

A security team is evaluating the following vulnerabilities in response to a third-party risk assessment:

Given the following organizational policy requirements:

  • Any adjusted CVSS score of 7.0 or greater must be remediated within

15 days.

  • Any adjusted CVSS score of 6.9 or less must be remediated within 30

days.

  • Any vulnerability with a known public exploit must be remediated

within seven days.

  • Any vulnerability that requires high privileges can have a lower

severity. Which of the following actions should the analyst do to meet the requirements on time?

Exhibits

CAS-005 question #497 exhibit 1
CAS-005 question #497 exhibit 2

Options

  • AImplement a patch for CVE-2025-1234.
  • BAccept risk for CVE-2022-5678.
  • CMake an exception within the insurance policy for CVE-2022-5678.
  • DAdd CVE-2024-9123 to the risk register.
  • EDecommission the systems affected by CVE-2024-9123.

How the community answered

(55 responses)
  • A
    60% (33)
  • B
    5% (3)
  • C
    9% (5)
  • D
    2% (1)
  • E
    24% (13)

Explanation

CVE-2025-1234 has an adjusted CVSS score of 7.1, which meets the policy requirement for remediation within 15 days. The other vulnerabilities (5.6 and 6.9) fall below the 7.0 threshold and can be remediated within 30 days, so the immediate action is to implement a patch for CVE-

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice