A hybrid enterprise scans on-prem servers and IaaS workloads. Findings include critical internet-facing web vulnerabilities, high-severity internal server issues, and low-severity internal workstation issues. Business impact includes customer-facing outage risk and regulated data exposure. Which remediation SLA schedule best assigns due dates based on risk tier and business impact?
Select an answer to reveal the explanation.
Short Explanation
Think about it like this: you don't patch every hole on the same schedule if one is on the front door and one is in a back closet. Critical, internet-facing, regulated-data issues need the shortest clock, while internal low-severity items can wait longer. That's how you turn risk tier into real due dates.
Full Explanation
Remediation SLAs translate risk into operational deadlines by combining vulnerability severity with exposure and business impact. A critical finding on an internet-facing asset presents a high likelihood of exploitation and potential customer or data exposure, so it warrants the shortest due date. Internal high-severity findings still require prompt closure but typically have less immediate exposure, while internal low-severity findings can be scheduled longer without increasing enterprise risk. The wrong schedule that gives critical internet-facing findings a thirty-day window treats severity as the only input and ignores exposure, allowing an externally reachable weakness to persist despite its exploitability. The uniform schedule that applies one clock to every critical finding, regardless of exposure, simplifies reporting but fails to differentiate between a public-facing entry point and a segmented internal system. The schedule that assigns the shortest deadline to low-severity internal findings mistakes remediation effort for risk, because easy fixes should not outrank high-impact, exploitable conditions. Exam caveat: CS0-004 expects you to prioritize by risk, not by scan severity alone or by ticket volume. Operational check: validate the SLA matrix against asset inventory, internet exposure, data classification, and compensating controls before publishing due dates.