A vulnerability scanner exports a CVSS v4 finding for an internal file server. The base score is critical, but exploit maturity is unproven and threat intelligence confidence is low. What should the analyst do?
Select an answer to reveal the explanation.
Short Explanation
Think of CVSS v4 like a weather report: the base score tells you the storm’s size, but threat context tells you whether it’s actually heading toward your town. You don’t ignore a critical hole just because exploit maturity is unproven, and you don’t sprint on it just because the number looks scary. Use the threat context to set the real urgency.
Full Explanation
CVSS v4 separates inherent vulnerability severity from current threat conditions. The base score describes the vulnerability’s impact and exploitability in isolation, while threat metrics such as exploit maturity, threat source, threat confidence, and threat intelligence describe whether the weakness is being actively exploited or widely available. An analyst therefore adjusts remediation urgency by combining base severity with those threat indicators and asset context. Relying only on the base score discards the exploitability and threat-confidence context that CVSS v4 adds, so a critical base score may not always mean immediate action. Treating a finding as not urgent until exploit code exists is also wrong because unproven maturity does not mean the vulnerability is absent or harmless; it only means the current public or internal threat signal is weak. Escalating immediately solely because the base score is critical ignores the threat context and can waste response capacity on a high-severity but currently unexploited issue. Exam caveat: CS0-004 expects you to interpret CVSS v4 as a risk-adjustment framework, not as a single fixed priority number. Operational check: review the exploit maturity and threat-confidence fields in the scanner export, then compare them against asset criticality and EDR telemetry before assigning the remediation SLA.