nerdexam
CompTIA

CS0-003 · Question #648

The security team is reviewing a list of vulnerabilities present on the environment, and they want to prioritize the remediation based on the CVSS v4.0 metrics: Which of the following vulnerabilities

The correct answer is D. System D. The vulnerability on System D has the most severe combination of base metrics: it is exploitable over the network with low complexity, requires only low privileges, and no user interaction. Its exploit maturity is also above “unknown” (functional), indicating real, working exploi

Submitted by femi9· Mar 6, 2026Vulnerability Management

Question

The security team is reviewing a list of vulnerabilities present on the environment, and they want to prioritize the remediation based on the CVSS v4.0 metrics:

Which of the following vulnerabilities should the security manager request to fix first?

Exhibit

CS0-003 question #648 exhibit

Options

  • ASystem A
  • BSystem B
  • CSystem C
  • DSystem D
  • ESystem E

How the community answered

(23 responses)
  • A
    13% (3)
  • C
    9% (2)
  • D
    74% (17)
  • E
    4% (1)

Explanation

The vulnerability on System D has the most severe combination of base metrics: it is exploitable over the network with low complexity, requires only low privileges, and no user interaction. Its exploit maturity is also above “unknown” (functional), indicating real, working exploit code exists. This combination makes it the highest-priority issue to remediate first.

Topics

#CVSS#vulnerability prioritization#risk management#remediation

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice