nerdexam
CompTIA

CS0-003 · Question #28

An analyst is reviewing a vulnerability report for a server environment with the following entries: Which of the following systems should be prioritized for patching first?

The correct answer is D. 54.74.110.228. Prioritizing patching involves assessing vulnerability severity, system criticality, and exposure to determine which systems require immediate attention.

Submitted by minji_kr· Mar 6, 2026Vulnerability Management

Question

An analyst is reviewing a vulnerability report for a server environment with the following entries:

Which of the following systems should be prioritized for patching first?

Exhibit

CS0-003 question #28 exhibit

Options

  • A10.101.27.98
  • B54.73.225.17
  • C54.74.110.26
  • D54.74.110.228

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    10% (5)
  • D
    84% (43)

Why each option

Prioritizing patching involves assessing vulnerability severity, system criticality, and exposure to determine which systems require immediate attention.

A10.101.27.98

An internal IP (10.101.27.98) is generally prioritized lower for initial patching than public-facing systems unless it is critical for internal operations and has an easily exploitable, high-severity vulnerability.

B54.73.225.17

This is a public IP, but the implied vulnerability report suggests that 54.74.110.228 has a higher combined risk or more severe vulnerability, making it the top priority.

C54.74.110.26

This is also a public IP, but the context indicates 54.74.110.228 has the highest prioritization based on the unseen details of the vulnerability report, likely due to a more critical vulnerability or service.

D54.74.110.228Correct

Without the specific vulnerability report, the selection of 54.74.110.228 as the highest priority implies it hosts a critical service, is publicly accessible, and/or has a high-severity vulnerability that warrants immediate patching. Prioritizing public-facing systems with critical flaws is essential to prevent external exploitation.

Concept tested: Vulnerability prioritization

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/tvm-priorities?view=o365-worldwide

Topics

#Vulnerability prioritization#Vulnerability management#Risk assessment#Patch management

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice