Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 2Objective 3

Vulnerability Prioritization CS0-003 Practice Questions (Page 5)

Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
30%of the exam

Questions 21–24

  1. 21application · medium

    A vulnerability scanner reports a critical-severity (CVSS 9.8) remote code execution vulnerability in the web server software running on a legacy internal reporting server. This server is not accessible from the internet, is isolated in a segmented network, and is scheduled for decommissioning in 60 days. The vulnerability has a known public exploit. Which factor should MOST strongly influence the prioritization decision?

    Select an answer first
  2. 22expert · hard

    A vulnerability scanner reports a CVSS 9.0 vulnerability in a public-facing web application. The application is a customer portal that handles payment information. The vulnerability is a buffer overflow that requires the attacker to send a specially crafted request. The organization has a WAF that can be configured to block the attack pattern. The team has limited resources and must decide whether to patch the application or configure the WAF. What is the MOST important consideration?

    Select an answer first
  3. 23application · medium

    A zero-day vulnerability is announced in a popular VPN appliance used by an organization. The vendor has not released a patch, and there are reports of active exploitation in the wild. The appliance is used for remote access by all employees. What is the MOST appropriate immediate action?

    Select an answer first
  4. 24foundation · easy

    Which factor is most directly considered when assessing the exploitability of a vulnerability?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CS0-003

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.