An analyst reviews a vulnerability scanner report. A medium CVSS vulnerability affects an isolated internal workstation used only for local testing, with no sensitive data and no outbound internet access. Which remediation decision is best?
Select an answer to reveal the explanation.
Short Explanation
Think of risk like a flood: a leaky roof in a storage shed isn't the same as one over your server room. You lower priority when exposure and business impact are small. Don't let the word 'medium' shout louder than the actual blast radius.
Full Explanation
Vulnerability prioritization combines severity with context. CVSS gives intrinsic severity, but exposure and impact decide urgency. An isolated internal workstation with no sensitive data and no outbound access has low exposure, so the medium finding can be handled during routine maintenance rather than emergency remediation. The analyst still confirms asset value, connectivity, and compensating controls before lowering priority. Escalating solely because the CVSS score is medium ignores exploitability and business impact, treating all medium findings as equal. Immediate patching is excessive when the asset is isolated and noncritical, consuming analyst and change-control capacity without reducing meaningful risk. Accepting the risk outright skips due diligence; even low-exposure findings require confirming isolation, data sensitivity, and whether compensating controls remain effective. Exam caveat: CompTIA often expects you to weigh CVSS against asset exposure and data sensitivity rather than relying on score alone. Operational check: Verify the workstation's network segment, firewall rules, outbound connectivity, and asset inventory classification before recording a reduced remediation priority.