Quiz 8 Question 8 of 20

An internet-facing web application has a CVSS 9.1 vulnerability. The vulnerability scanner cannot confirm exploitability, but the WAF has a virtual patch blocking known exploit traffic. How should the analyst adjust risk priority?

Select an answer to reveal the explanation.

Motivation