312-50 exam dumps

312-50 practice question 124 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 124

Single answer▪ Vulnerability Assessment Reports

A security consultant completes a vulnerability assessment for a midsize company and delivers a report showing 120 findings. The CIO is concerned because the report lists several Critical vulnerabilities, including one on an internal development server that is isolated from production, while an internet-facing VPN gateway with a High-severity finding is used by all remote employees. The CIO asks which issue should be remediated first. Which action should the consultant recommend based on vulnerability assessment reporting best practices?

  1. A

    Prioritize the internal development server because Critical findings must always be fixed before High findings

  2. B

    Prioritize the internet-facing VPN gateway because remediation should consider business context, exploitability, and exposure, not just raw severity

  3. C

    Remediate all informational and low findings first to reduce the total number of items in the report before addressing severe issues

  4. D

    Delay remediation until a full penetration test confirms whether each reported vulnerability is exploitable in practice

Show answer and explanation

Correct answer: B

Explanation

The best answer is to prioritize the internet-facing VPN gateway because vulnerability assessment reports are most useful when they support risk-based remediation decisions. In practice, remediation priority should consider more than the scanner's severity rating. Key factors include whether the asset is internet-facing, how critical it is to business operations, whether reliable exploits exist, the sensitivity of the data or access involved, and whether compensating controls reduce risk. This aligns with common guidance from frameworks and standards such as NIST's Risk Management Framework concepts, NIST SP 800-40 guidance on enterprise patch management, and CVSS documentation, which notes that base severity should be supplemented with environmental context. In CEH-style scenarios, the candidate should recognize that a vulnerability assessment report is not just a list of findings, it is a decision-making tool for prioritizing remediation based on real-world risk.

  • A. Incorrect.

    This is incorrect because vulnerability assessment reports should not be prioritized solely by scanner severity labels. A Critical vulnerability on an isolated internal development server may present less immediate risk than a High vulnerability on an internet-facing VPN gateway that supports business-critical remote access. The misconception is treating CVSS or scanner severity as the only decision factor, ignoring exposure, asset value, compensating controls, and likelihood of exploitation.

  • B. Correct.

    This is correct because effective vulnerability assessment reporting ties technical findings to business risk. An internet-facing VPN gateway is externally exposed, often high-value, and frequently targeted. Best practice is to prioritize based on risk-informed factors such as attack surface, exploitability, business impact, and asset criticality rather than severity alone. In this scenario, the VPN gateway presents a more urgent remediation priority despite being labeled High instead of Critical.

  • C. Incorrect.

    This is incorrect because reducing the total count of findings does not reduce the organization's most significant risk. Informational and Low findings are typically handled after higher-risk items unless there is a specific compliance or operational reason. This option reflects a common reporting mistake: focusing on cosmetic metrics rather than risk reduction.

  • D. Incorrect.

    This is incorrect because a vulnerability assessment report is already intended to support remediation planning. While penetration testing can help validate exploitability and demonstrate impact, organizations should not postpone remediation of clearly risky findings, especially on exposed systems, while waiting for additional testing. This approach can unnecessarily extend the window of exposure.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam