CompTIA CySA+ CS0-003 Practice Question

A security analyst is tasked with the vulnerability management process in an organization that follows strict regulatory compliance. After the latest vulnerability scan, several issues have been identified, but due to resource constraints not all can be immediately addressed. Which of the following should be the FIRST step in prioritizing which vulnerabilities to mitigate?

  • Prioritize based on which vulnerabilities require a patch available from the software vendor.

  • List the vulnerabilities in descending order of asset criticality.

  • Apply risk management principles to determine the level of threat each vulnerability poses to the organization.

  • Rank the vulnerabilities based on the potential scope of impact alone.

CompTIA CySA+ CS0-003
Vulnerability Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot