PT0-001 · Question #8
A penetration tester has performed a security assessment for a startup firm. The report lists a total of ten vulnerabilities, with five identified as critical. The client does not have the resources…
The correct answer is D. Fix the most critical vulnerability first, even if it means fixing the other vulnerabilities may take a. When remediation resources are constrained, vulnerability prioritization should be driven by risk severity rather than remediation ease, ensuring the highest-impact threats are closed first.
Question
A penetration tester has performed a security assessment for a startup firm. The report lists a total of ten vulnerabilities, with five identified as critical. The client does not have the resources to immediately remediate all vulnerabilities. Under such circumstances, which of the following would be the BEST suggestion for the client?
Options
- AApply easy compensating controls for critical vulnerabilities to minimize the risk, and then
- BIdentify the issues that can be remediated most quickly and address them first.
- CImplement the least impactful of the critical vulnerabilities' remediations first, and then address
- DFix the most critical vulnerability first, even if it means fixing the other vulnerabilities may take a
How the community answered
(32 responses)- A3% (1)
- B13% (4)
- C3% (1)
- D81% (26)
Why each option
When remediation resources are constrained, vulnerability prioritization should be driven by risk severity rather than remediation ease, ensuring the highest-impact threats are closed first.
Applying compensating controls to critical vulnerabilities without fully remediating them reduces risk only temporarily and may create a false sense of security while the underlying vulnerability remains exploitable.
Sequencing remediation by speed rather than severity means lower-risk findings may be closed first while critical vulnerabilities stay open and exploitable for a longer period.
Implementing the least impactful critical remediation first delays addressing the highest-severity issues, leaving the most dangerous vulnerabilities unresolved and increasing overall organizational risk during the remediation window.
Fixing the most critical vulnerability first aligns with risk-based remediation methodology, as critical-severity findings carry the greatest potential business impact and exploitability; addressing lower-priority issues first while a critical vulnerability remains open maximizes the window of exposure to the most significant threat.
Concept tested: Risk-based vulnerability remediation prioritization
Source: https://csrc.nist.gov/publications/detail/sp/800-40/r4/final
Topics
Community Discussion
No community discussion yet for this question.