SY0-701 exam dumps

SY0-701 practice question 298 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 298

Single answer

A security analyst at a healthcare company reviews the weekly vulnerability scan results. The scanner reports CVE-2024-XXXX on 150 internal application servers with a base CVSS score of 9.8. Initial review shows the affected service is disabled on most of the servers, and network segmentation prevents direct access from untrusted networks. However, 12 internet-facing billing servers do run the vulnerable service, process regulated patient data, and are part of a business-critical revenue system. The organization's risk tolerance for systems handling ePHI is very low. What should the analyst do FIRST to most appropriately prioritize remediation?

  1. A

    Treat all 150 findings as equally critical because the CVSS base score is 9.8 and immediately schedule emergency patching for every server

  2. B

    Confirm which systems are actually vulnerable, identify false positives, and prioritize the 12 internet-facing billing servers using environmental and business impact factors

  3. C

    Ignore the finding unless there is active exploitation in the wild, because CVE entries alone do not justify remediation

  4. D

    Lower the severity of all findings because network segmentation fully eliminates the risk posed by the vulnerability

Show answer and explanation

Correct answer: B

Explanation

The best answer is to confirm the findings and then prioritize remediation based on actual risk. In vulnerability analysis, a scanner finding tied to a CVE should be validated to determine whether it is a true positive or a false positive. If the vulnerable service is disabled, the host may not actually be affected in an exploitable way. After confirmation, prioritization should consider more than the CVSS base score. The National Vulnerability Database and FIRST's CVSS guidance distinguish between base metrics and environmental considerations. Environmental variables such as internet exposure, asset role, compensating controls, and data sensitivity materially affect prioritization. In this scenario, the 12 internet-facing billing servers represent the highest priority because they are exposed, process ePHI, support critical business operations, and fall under a low risk tolerance environment typical of healthcare. This aligns with common best practice: validate findings, classify the vulnerability correctly, account for exposure factor and business impact, and then remediate according to organizational risk tolerance rather than relying on scanner output alone.

  • A. Incorrect.

    This is incorrect because CVSS base scores are only one input into prioritization. Treating every asset identically ignores confirmation, false-positive analysis, exposure, environmental variables, and organizational impact. Security+ expects candidates to understand that remediation should be risk-based, not driven solely by the base score.

  • B. Correct.

    This is correct because the analyst should first validate whether the scanner results reflect actual exposure and remove false positives where the service is disabled. After confirmation, the 12 internet-facing billing servers should be prioritized because they have higher exposure, greater business impact, and stricter risk tolerance due to regulated patient data. This reflects practical vulnerability analysis using CVE identification, CVSS context, environmental variables, and industry/organizational impact.

  • C. Incorrect.

    This is incorrect because waiting for evidence of active exploitation is not an appropriate first step for a high-severity vulnerability affecting critical systems. A CVE identifies a known vulnerability, and organizations should assess and prioritize based on risk, not dismiss findings until attacks are observed. This option reflects the misconception that threat activity is required before remediation is justified.

  • D. Incorrect.

    This is incorrect because segmentation can reduce exposure but does not fully eliminate risk, especially for internet-facing systems. It also does not address whether the vulnerable service is enabled on specific hosts. Assuming compensating controls completely negate the issue can lead to false negatives in prioritization and delayed remediation of genuinely exposed assets.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam