How Should Organizations Prioritize Vulnerabilities Most Effectively?
Which of the following should an organization focus on the most when making decisions about vulnerability prioritization?
Community Votes
64% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between standardized technical severity scoring and contextual business risk metrics, with the common trap being the intuitive selection of 'exposure factor' over the universally adopted CVSS framework.
This question evaluates the primary metric used for technical vulnerability prioritization, with the community consensus firmly pointing to CVSS as the industry standard. While exposure factor reflects organizational risk, CVSS provides the standardized, quantifiable scoring framework necessary for systematic threat triage.
Candidates frequently choose Exposure Factor, reasoning that it directly measures potential business damage, data sensitivity, and likelihood of exploitation. However, this represents a qualitative risk assessment component rather than the universal, objective baseline required for initial vulnerability triage and patch management workflows.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Standardized Vulnerability Scoring
The Common Vulnerability Scoring System (CVSS) is the globally recognized standard for evaluating and ranking the severity of software vulnerabilities. As highlighted by candidate jbmac, CVSS provides a standardized numerical score (0–10) derived from base, temporal, and environmental metrics that assess exploitability, impact, and complexity. This quantifiable approach allows security teams to objectively rank thousands of discovered flaws and allocate remediation resources efficiently.Why CVSS Outweighs the Alternatives
While CVE (Option C) assigns a unique identifier to each vulnerability, it carries no inherent severity rating and therefore cannot drive prioritization. Industry impact (Option D) is too subjective and lacks the granular technical data needed for operational decision-making. Although Exposure Factor (Option A) accurately reflects potential financial or reputational loss, it is typically calculated during a formal risk assessment phase rather than serving as the primary driver for day-to-day vulnerability management triage. As user ProudFather points out, exposure factor focuses on potential damage, but as candidate b82faaf correctly notes, CVSS encompasses a broader range of technical considerations than raw exposure percentages, making it the foundational metric for prioritization workflows.Exam Strategy Application
On the SY0-701 exam, CompTIA consistently favors standardized frameworks and measurable metrics over subjective or high-level business concepts unless the scenario explicitly targets executive reporting or risk acceptance. When you encounter vulnerability prioritization questions, default to CVSS or EPSS as your primary answer, reserving exposure or business impact options for contexts involving governance, compliance, or ROI analysis.Official Reference
- https://www.first.org/cvss/specification-document
- https://nvd.nist.gov/vuln-metrics/cvss
- CompTIA Security+ SY0-701 Exam Objectives - Domain 4.5: Identify and describe the purpose/characteristics of common vulnerabilities
Exam Strategy
When faced with vulnerability prioritization questions, always prioritize standardized scoring frameworks like CVSS over qualitative business metrics. Reserve options related to exposure or financial impact for scenarios explicitly asking about risk acceptance, executive reporting, or formal risk assessments, as technical triage relies on quantifiable severity baselines.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →