nerdexam
CompTIA

CS0-003 · Question #222

A company recently removed administrator rights from all of its end user workstations. An analyst uses CVSSv3.1 exploitability metrics to prioritize the vulnerabilities for the workstations and…

The correct answer is D. great.skills. The vulnerability to be prioritized should be the one with the greatest impact on the system. Given that the complexity of the attack is low (AC=L), that no privileges are required (PR=N) and no user interaction is required (UI=N).

Submitted by yuriko_h· Mar 6, 2026Vulnerability Management

Question

A company recently removed administrator rights from all of its end user workstations. An analyst uses CVSSv3.1 exploitability metrics to prioritize the vulnerabilities for the workstations and produces the following information:

Which of the following vulnerabilities should be prioritized for remediation?

Exhibit

CS0-003 question #222 exhibit

Options

  • Anessie.explosion
  • Bvote.4p
  • Csweet.bike
  • Dgreat.skills

How the community answered

(47 responses)
  • A
    21% (10)
  • B
    15% (7)
  • C
    6% (3)
  • D
    57% (27)

Explanation

The vulnerability to be prioritized should be the one with the greatest impact on the system. Given that the complexity of the attack is low (AC=L), that no privileges are required (PR=N) and no user interaction is required (UI=N).

Topics

#vulnerability prioritization#CVSS#risk assessment#privilege management

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice