CompTIA CySA+ CS0-003 Practice Question
A recently conducted vulnerability scan has presented a vast number of potential security issues. What strategy should be used to prioritize which vulnerabilities to address first?
Always addressing the vulnerabilities related to regulatory requirements before any other issues
Prioritizing based on the ease of implementation of the available patches
Applying the asset value and the potential impact to confidentiality, integrity, and availability (CIA) to prioritize which vulnerabilities to address first
Following the recommendations from the proprietary algorithm of the vulnerability scanning tool