A scanner reports a critical web server vulnerability with a public exploit and the service is reachable from the internet. The server hosts an internal application behind a WAF. Which remediation action is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Think of prioritization like triage: if the hole is big, the door is open, and the bad guy already has the key, you don't wait. You patch it now, then worry about paperwork later.
Full Explanation
The mechanism is risk alignment: a critical CVSS score indicates potential impact, a public exploit raises likelihood, and reachable service exposure removes the main barrier to attack. Together they justify placing the finding at the top of the remediation queue, ideally through emergency change and patching, because the condition is both severe and actively exploitable. A scheduled maintenance window is inappropriate when compensating controls do not eliminate the known exploit path, because maintenance cadence is a control for operational disruption, not a substitute for urgent exposure reduction. Lowering priority because no compromise has been confirmed misunderstands vulnerability management: prevention is based on likelihood and impact, not incident confirmation. Risk acceptance is only defensible when exposure is constrained, exploitability is low, or business constraints are documented; here public exploitability and internet reachability make acceptance weak. Exam caveat: prioritize using exploitability, exposure, asset value, and impact, not CVSS alone. Operational check: confirm the vulnerable service is externally reachable, apply the vendor patch in an emergency change, then rescan to verify closure.