nerdexam
CompTIA

CS0-003 · Question #245

A security analyst performs a vulnerability scan. Based on the metrics from the scan results, the analyst must prioritize which hosts to patch. The analyst runs the tool and receives the following out

The correct answer is C. host03. Host03 should be patched first, based on the metrics, as it has the highest risk score and the highest number of critical vulnerabilities. The risk score is calculated by multiplying the CVSS score by the exposure factor, which is the percentage of systems that are vulnerable to

Submitted by ricky.ec· Mar 6, 2026Vulnerability Management

Question

A security analyst performs a vulnerability scan. Based on the metrics from the scan results, the analyst must prioritize which hosts to patch. The analyst runs the tool and receives the following output:

Which of the following hosts should be patched first, based on the metrics?

Exhibit

CS0-003 question #245 exhibit

Options

  • Ahost01
  • Bhost02
  • Chost03
  • Dhost04

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    5% (2)
  • C
    84% (32)
  • D
    3% (1)

Explanation

Host03 should be patched first, based on the metrics, as it has the highest risk score and the highest number of critical vulnerabilities. The risk score is calculated by multiplying the CVSS score by the exposure factor, which is the percentage of systems that are vulnerable to the exploit. Host03 has a risk score of 10 x 0.9 = 9, which is higher than any other host. Host03 also has 5 critical vulnerabilities, which are the most severe and urgent to fix, as they can allow remote code execution, privilege escalation, or data loss. The other hosts have lower risk scores and lower numbers of critical vulnerabilities, so they can be patched later.

Topics

#Vulnerability prioritization#Vulnerability metrics#Patch management#Risk assessment

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice