A vulnerability scanner reports a medium-severity CVE on an internet-facing web server. Threat intelligence confirms the CVE is being actively exploited in the wild, but internal logs show no compromise indicators. What should the vulnerability analyst do?
Select an answer to reveal the explanation.
Short Explanation
Think of CVSS base severity like a car's crash rating: useful, but it doesn't tell you how many cars are already speeding toward your garage. If a medium bug is being actively exploited, you bump it up because the odds of being hit just went way up. Don't let the word "medium" lull you into a slow patch cycle.
Full Explanation
Prioritization should combine severity with exploitability and asset exposure. A medium CVSS base score describes potential impact and exploitability in isolation, but active exploitation in the wild is a strong indicator that the vulnerability is being used by adversaries now. For an internet-facing server, that raises the likelihood of compromise enough to warrant immediate remediation, compensating controls, or isolation while a patch is developed. Scheduling the finding for a routine patch cycle ignores the changed risk condition; base severity alone is no longer the dominant factor. Reducing priority because internal logs show no compromise confuses detection with prevention, since absence of evidence is not evidence that exploitation will not occur. Waiting for a higher-severity exploit against the same CVE delays response to a known, already-abused weakness and allows attackers to benefit from the gap. Exam caveat: CS0-004 expects you to weigh CVSS alongside threat intelligence, exposure, and asset value rather than treating a single score as final. Operational check: Review the CVE against the CISA Known Exploited Vulnerabilities catalog or your threat-intel feed, then escalate the ticket and verify compensating controls such as WAF rules or network isolation.