A scanner report shows the same CVE on 600 hosts, including domain controllers, web servers, and lab VMs. Which remediation ranking approach is best?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a hospital ER: you don't treat patients by how many bandages they have, you treat the most critical first. The same CVE on 600 hosts can still be a fire on a domain controller and a smolder on a lab VM. You rank by what the asset does and how exposed it is, not by scan clutter.
Full Explanation
Vulnerability assessment output often produces massive duplicate findings for a single CVE. A defensible remediation ranking converts raw scan output into risk context by weighting asset criticality, network exposure, data sensitivity, compensating controls, and current threat intelligence. This approach aligns with vulnerability management best practice because identical technical findings can have materially different business impact. A finding on a public-facing domain controller, internet-facing web server, or privileged management system generally outranks the same finding on an isolated lab host or low-impact workstation.
Ranking by total findings per host is flawed because scan noise, agent coverage, and operating-system inventory can inflate counts without indicating risk. Ranking by scan age is also flawed because an older scan may be accurate and urgent, while a recent scan may cover a low-value asset. Ranking by network segment name or size is flawed because segment labels do not reveal business criticality, internet exposure, or data sensitivity.
Exam caveat: CS0-004 expects analysts to prioritize based on risk, not raw scanner volume or administrative convenience. Operational check: Enrich scanner export with CMDB criticality, exposure flags, and threat-intel matches before assigning remediation queues.