Question 1 of 30
The risk matrix shows a critical vulnerability identified with a CVSS v3.1 score of 9.8 (Critical). The affected system is a web server hosting a public-facing marketing website with no access to sensitive customer data. The organization has limited remediation resources. Which of the following approaches best guides the immediate response to this identified vulnerability?
Prioritize remediation based on the CVSS score, but also consider the criticality of the affected asset, the current threat landscape, and the potential business impact to inform the urgency and resource allocation for remediation.
Immediately allocate all available remediation resources to address this vulnerability, as its critical CVSS score dictates it is the highest priority regardless of the asset's function or data sensitivity.
Defer remediation of this vulnerability until there is evidence of active exploitation in the wild, as the marketing website does not handle sensitive data.
Classify this vulnerability as low priority due to the non-sensitive nature of the data hosted on the marketing website, despite its critical CVSS score, and focus resources on other systems.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free