Worth 26% of the CompTIA CySA+ (CS0-004) exam. CertClue has 77 questions on this objective.
What this objective covers
CVSS Scoring and Risk-Based Vulnerability Prioritization
CVSS gives every vulnerability a consistent severity score, but severity alone does not tell an analyst what to fix first. Real prioritization blends the base score with exploitability in the wild and the criticality of the asset it affects.
Exam tip. If a question presents a lower CVSS score on an exposed, actively exploited system next to a higher score on an isolated system, the exposed and exploited one is remediated first.
Practice questions
Free, with the answer and the reasoning. No account needed.
1. A vulnerability report shows a finding with a high CVSS base score, but the affected component is isolated on a network segment with no connectivity to any other system and no user access. How should this context affect the finding's remediation priority relative to its raw CVSS score?
A. The effective risk should be reduced because the environmental context significantly limits exploitabilitycorrect
B. The CVSS score itself should be manually edited to zero
C. The priority should increase because isolated systems are always attacked first
D. Isolation has no bearing on remediation priority
CVSS environmental metrics exist precisely to adjust a base score for real deployment context, and a fully isolated, unreachable system with no user access has meaningfully reduced real-world exploitability regardless of its base severity, justifying a lower effective remediation priority than the raw score alone suggests. Isolated systems are not inherently attacked first, since isolation is a defensive control, editing a published base score directly is not appropriate practice, and claiming isolation has no bearing ignores exactly the kind of contextual risk adjustment CySA+ expects analysts to apply.
2. A vulnerability scan returns a finding with a CVSS base score of 9.8. Which severity band does this score fall into under the standard CVSS qualitative rating scale?
A. Informational
B. Low
C. Criticalcorrect
D. Medium
Under the standard CVSS v3.x qualitative rating scale, scores from 9.0 to 10.0 fall into the Critical band, which is where 9.8 lands. Medium covers 4.0 to 6.9, Low covers 0.1 to 3.9, and Informational is not a standard CVSS severity band at all, findings are always rated on the numeric-to-qualitative scale from None through Critical.
3. Thornbury Retail's vulnerability management team wants to run a full authenticated scan of its point-of-sale network but is concerned about impacting transaction processing during business hours. What is the most appropriate scheduling approach?
A. Run the scan continuously in the background at all times to maximize detection speed
B. Skip scanning the point-of-sale network entirely since it is considered too sensitive to test
C. Schedule the scan during a defined maintenance window outside business hours and coordinate with the operations team in advancecorrect
D. Run the scan only once per year during the annual PCI assessment to minimize any operational impact
Scheduling resource-intensive scans during a coordinated maintenance window outside business hours minimizes the risk of disrupting sensitive operational systems like point-of-sale networks while still maintaining regular scanning coverage. Running continuously risks ongoing disruption, skipping the network leaves it unassessed, and scanning only annually leaves vulnerabilities undetected for far too long between assessments.
Work the whole objective
The full CompTIA CySA+ bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.