Question 1 of 30
Quality control measures reveal a new vulnerability with a CVSS v3.1 score of 9.8 (Critical). The vulnerability affects a web server that hosts a public-facing marketing website. The marketing team has indicated that this website is crucial for lead generation and brand visibility, but it does not handle any sensitive customer data or financial transactions. Given this information, which of the following is the most appropriate next step for the security analyst?
Initiate a comprehensive risk assessment by correlating the CVSS score with the business criticality of the web server and the potential impact on lead generation and brand visibility, to determine the appropriate remediation priority.
Immediately escalate the vulnerability for emergency patching across all affected systems, prioritizing it above all other ongoing security tasks.
Classify the vulnerability as low priority for remediation because the affected system does not handle sensitive data or financial transactions, despite its high CVSS score.
Focus remediation efforts solely on mitigating the exploitability metrics of the CVSS score, as this is the primary indicator of immediate threat.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free