An enterprise SOC receives a scanner report: a high-severity authentication bypass CVE affects an internet-facing SSO gateway used by privileged admins. The gateway has no compensating controls and sits in a DMZ. Which remediation decision best aligns with vulnerability prioritization?
Select an answer to reveal the explanation.
Short Explanation
Think of prioritization like triage in a busy clinic: a severe wound, an open door to the street, and a VIP patient all scream first. You don't wait for a patch window or a user email when an internet-facing auth server can let attackers in. Severity, exposure, and asset criticality are the three dials that should move together.
Full Explanation
Vulnerability prioritization is not a single metric; it combines technical severity, exposure, and business criticality. A high-severity authentication bypass on an internet-facing authentication gateway creates a credible path to compromise because authentication controls protect downstream systems. The asset's use by privileged administrators raises impact, while direct internet exposure increases exploitation likelihood. Together these factors justify immediate patching or compensating mitigation ahead of lower-risk findings.
A quarterly maintenance delay is weak because severity alone is not the only input, but exposure and asset criticality can override routine scheduling when a direct attack path exists. Waiting for user notification is also misplaced because communication supports response operations but does not determine remediation urgency for an exploitable authentication control. Treating internet-facing DMZ systems as lower risk is wrong; perimeter placement does not neutralize a high-severity authentication flaw and often increases risk.
Exam caveat: choose the answer that weighs multiple factors instead of relying only on CVSS severity, patch cycles, or network placement. Operational check: confirm the asset owner, internet-facing status, authentication dependency, and available mitigation, then document the priority decision in the vulnerability ticket.