nerdexam
CompTIA

CS0-003 · Question #656

A security analyst is analyzing two vulnerabilities on a critical router. The analyst must choose only one to patch during this maintenance window. Given the following information: Vulnerability 1 has

Sign in or unlock CS0-003 to reveal the answer and full explanation for question #656. The question stem and answer options stay visible for context.

Submitted by javi_es· Mar 6, 2026Vulnerability Management

Question

A security analyst is analyzing two vulnerabilities on a critical router. The analyst must choose only one to patch during this maintenance window. Given the following information:

Vulnerability 1 has not received a CVSS score. The vulnerability has the following characteristics:

  • Must be logged in to the router, but elevated privileges are not

required

  • Trivial to exploit, but user interaction is needed
  • Low impact to availability, but high impact to confidentiality and

integrity Vulnerability 2 has a CVSS score of AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H Which of the following conclusions should the analyst reach?

Options

  • APatch Vulnerability 1 because it has a higher overall impact when looking at confidentiality,
  • BPatch Vulnerability 1 because it is easier to exploit and has a higher impact on confidentiality.
  • CPatch Vulnerability 2 because it has a higher overall impact when looking at confidentiality,
  • DPatch Vulnerability 2 because it is easier to exploit, has a high impact on availability, and it is

Unlock CS0-003 to see the answer

You've previewed enough free CS0-003 questions. Unlock CS0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Vulnerability prioritization#CVSS scoring#Vulnerability assessment#Risk analysis
Full CS0-003 Practice