nerdexam
CompTIA

CS0-003 · Question #220

The vulnerability analyst reviews threat intelligence regarding emerging vulnerabilities affecting workstations that are used within the company: Which of the following vulnerabilities should the…

The correct answer is A. Vulnerability A. Given that end users frequently click malicious links, the analyst should prioritize vulnerabilities that are exploitable via client-side interaction through such links.

Submitted by brentm· Mar 6, 2026Vulnerability Management

Question

The vulnerability analyst reviews threat intelligence regarding emerging vulnerabilities affecting workstations that are used within the company:

Which of the following vulnerabilities should the analyst be most concerned about, knowing that end users frequently click on malicious links sent via email?

Exhibit

CS0-003 question #220 exhibit

Options

  • AVulnerability A
  • BVulnerability B
  • CVulnerability C
  • DVulnerability D

How the community answered

(50 responses)
  • A
    64% (32)
  • B
    6% (3)
  • C
    10% (5)
  • D
    20% (10)

Why each option

Given that end users frequently click malicious links, the analyst should prioritize vulnerabilities that are exploitable via client-side interaction through such links.

AVulnerability ACorrect

Vulnerabilities that can be exploited by users clicking malicious links (e.g., in web browsers or email clients) are the most critical concern when user behavior involves frequent clicking of such links. These client-side vulnerabilities, often leading to remote code execution or malware installation, directly leverage the identified user risk and should be remediated first to prevent immediate workstation compromise.

BVulnerability B

While serious, if 'Vulnerability B' refers to a vulnerability less directly exploitable by clicking a link (e.g., local privilege escalation), it would be a lower priority compared to direct exploitation via user interaction.

CVulnerability C

If 'Vulnerability C' refers to a vulnerability less directly exploitable by clicking a link (e.g., a denial-of-service), it would not pose the same immediate risk of workstation compromise as a direct client-side exploit.

DVulnerability D

If 'Vulnerability D' refers to a vulnerability less directly exploitable by clicking a link (e.g., information disclosure without immediate code execution), it would be a lower priority than a vulnerability that leverages user clicks for direct system compromise.

Concept tested: Vulnerability prioritization based on threat intelligence

Source: https://docs.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/tvm-priorities?view=o365-worldwide

Topics

#threat intelligence#vulnerability prioritization#social engineering#end-user risk

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice