A vulnerability scan reports CVE-1234 as Critical with CVSS 9.8 but no known exploit or threat actor activity, while CVE-5678 is High with CVSS 7.5 but has a public exploit and active threat-actor use. After feed enrichment, how should the analyst refine the scanner finding?
Select an answer to reveal the explanation.
Short Explanation
Think of CVSS like a building's flammability rating: it tells you how bad a fire could be, not whether someone just handed you a match. When a feed says an exploit is public and threat actors are using it, you should bump that finding up, even if another one has a shinier score. Don't let the raw number alone drive your queue.
Full Explanation
Vulnerability scanner output gives an intrinsic severity estimate, often CVSS, based on the flaw's technical properties. Enrichment overlays external threat data such as exploit availability, active exploitation, and threat-actor interest, which changes operational urgency. A finding with a lower base score but a public exploit and observed threat activity can present a higher real-world likelihood of attack than a critical finding with no known exploit, so the analyst should refine the raw scanner result by elevating the enriched threat context.
Keeping the higher CVSS item first ignores that CVSS describes potential impact and not current threat exposure. Relying only on scanner severity discards enrichment that is intended to reduce false urgency and focus remediation on realistic attack paths. Deprioritizing the lower-scoring item because it lacks a critical score reverses the purpose of threat-informed prioritization, since exploit availability and active actor use are direct indicators of elevated risk.
Exam caveat: When a question mentions enrichment feeds, look for external threat context beyond the scanner's base score. Operational check: Compare scanner severity with enrichment fields for exploit availability and active threat activity before assigning remediation priority.