A vulnerability scanner reports a Critical CVSS 9.8 rating for a remote code execution flaw on a domain controller. The DC is only reachable from a restricted management VLAN, requires authenticated access, and no public exploit is observed in your threat feed. What is the best way to use the scanner result?
Select an answer to reveal the explanation.
Short Explanation
Think of a scanner score like a weather alert: it tells you the storm is possible, not whether your house is in its path. You still check exposure, exploit chatter, and controls before deciding how urgent it is. Don't let a big CVSS number replace your analyst judgment.
Full Explanation
Scanner severity reflects the intrinsic impact and exploitability of a vulnerability, often from CVSS base or temporal factors, but it does not fully represent the environment. A final risk rating should combine scanner output with asset criticality, exposure, compensating controls, and current exploit intelligence. A remote code execution flaw on a domain controller remains serious, but authenticated access, a restricted VLAN, and no observed exploit lower likelihood without removing risk. Accepting the scanner rating as final ignores environmental context and can misdirect remediation. Downgrading to Low because segmentation exists can understate risk, especially for authentication bypass or later lateral movement. Escalating for emergency patching because scanner severity alone overrides controls is also unsound; controls change urgency, not the vulnerability's existence. Exam caveat: CVSS base metrics are not an environmental score, and scanner severity is not automatically the organization's risk rating. Operational check: Re-score the finding with environmental factors, verify network reachability and authentication requirements, and record whether a credible exploit or active threat activity exists before setting priority.