An analyst reviews a vulnerability scan and sees a critical finding on a database server that stores regulated customer data. The server is internal, heavily used by customer service, and has compensating network segmentation. Which factor should most strongly drive the remediation ranking?
Select an answer to reveal the explanation.
Short Explanation
Think of remediation like triage in an ER: a broken toe on a healthy person isn't worse than chest pain. If your database holds regulated customer data, that context should push it up the queue even if segmentation makes it harder to reach. You're ranking risk to the business, not just collecting scan numbers.
Full Explanation
Prioritization should follow risk, not raw scan severity. In vulnerability management, remediation ranking combines likelihood with impact; impact is shaped by the asset's business value, data sensitivity, regulatory obligations, and exposure. A database containing regulated customer data can elevate a finding because breach impact includes legal, financial, and reputational harm. Compensating controls such as segmentation may reduce likelihood, but they do not erase data criticality when comparing findings.
An answer focused only on disclosure age treats time as a proxy for risk, yet older findings may already be mitigated or less relevant, while newer ones may be irrelevant. Counting other vulnerabilities on the host measures noise or patch debt, not the consequence of this finding. Relying solely on the scanner's high or critical label ignores context: CVSS and vendor severity do not know that the asset stores regulated records or supports customer operations.
Exam caveat: when CVSS severity conflicts with business or data impact, choose the answer that reflects organizational risk and regulatory exposure. Operational check: tag the database with data classification, business owner, and compensating controls, then rank remediation using severity plus exposure plus data criticality.