Which of the following approaches provides the BEST basis for prioritizing remediation of vulnerabilities discovered during a security assessment?
Combine technical severity with asset criticality, exposure, business impact, exploit likelihood, and existing controls to create a risk-based ranking.
Address vulnerabilities in the order they were reported by the scanning tool.
Prioritize vulnerabilities strictly by their numerical severity rating (e.g., CVSS score) produced by automated scanners.
Remediate only the vulnerabilities that external auditors flag as non-compliant.
The most effective way to decide what to fix first is to use a risk-based approach that combines the technical severity of each vulnerability with contextual information such as asset criticality, exposure, exploit likelihood, business impact, data sensitivity, and any compensating controls. Relying on scanner scores alone (or on ticket order, audit findings, or other single-factor methods) can divert resources to issues that matter less to the organization while leaving higher-risk weaknesses unaddressed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CVSS and how does it impact vulnerability prioritization?
Open an interactive chat with Bash
Why is asset criticality important when assessing vulnerabilities?
Open an interactive chat with Bash
What are compensating controls, and how do they influence vulnerability prioritization?
Open an interactive chat with Bash
ISC2 CISSP
Security Assessment and Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .