What Most Impacts an Administrator's Ability to Address CVEs on a Server?
Which of the following most impacts an administrator's ability to address CVEs discovered on a server?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your understanding that without a vendor-supplied patch, an administrator cannot remediate a known CVE, regardless of scanning, risk, or organizational factors.
The CompTIA Security+ SY0-701 exam tests vulnerability management concepts, including how patch availability is the primary factor in addressing CVEs. Community consensus strongly favors patch availability as the correct answer.
Choosing 'Organizational impact' or 'Risk tolerance' is common because those factors influence prioritization, but they do not affect the ability to fix a vulnerability if no patch exists.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Patch availability is the direct enabler of remediation for a CVE. If a vendor has not released a patch, the administrator is unable to apply a fix, making all other considerations secondary. As one commenter noted, 'Patch availability is the most critical factor... because it directly determines whether a known vulnerability can be fixed through updates or patches provided by software vendors.' Another comment emphasizes that 'if patches are not available to fix the vulnerabilities, the administrator cannot remediate the issues.'Why the Other Options Are Wrong
Rescanning requirements (A) are part of the validation process after remediation, not the ability to address the CVE itself. Organizational impact (C) affects prioritization but not the technical capability to apply a fix. Risk tolerance (D) influences whether to accept the risk, but again does not determine whether a patch exists. The key is that 'ability' in the question refers to the existence of a remediation path, which is solely governed by patch availability.Community Comment Notes
All comments agree on B, with one providing a clear definition: 'Patch Availability refers to whether a vendor has released a software update or patch that addresses a specific vulnerability identified by a CVE.' Another comment directly states that without a patch, other factors are irrelevant, reinforcing the exam logic. The unanimous vote distribution (B: 100) further confirms the correct answer.Official Reference
Exam Strategy
When a question asks what 'most impacts an administrator's ability,' distinguish between factors that enable action versus those that influence decision-making. Patch availability is the only enabling factor here; the others are risk management considerations. Remember that remediation cannot occur without a patch.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →