A cloud vulnerability scan reports multiple storage misconfigurations across a hybrid estate. Some buckets contain regulated data, others contain non-sensitive files; some are public, others private. Which prioritization approach is most appropriate for remediation planning?
Select an answer to reveal the explanation.
Short Explanation
Think of cloud storage like leaving a filing cabinet outside: sensitive papers matter, but leaving them unlocked on the sidewalk matters more. You should fix the exposure that puts regulated data within public reach first. That's the kind of risk you can actually defend in a report.
Full Explanation
Prioritizing cloud storage exposure requires combining data sensitivity with reachability. A misconfiguration involving regulated, unencrypted, or otherwise sensitive data that is publicly reachable represents immediate confidentiality impact. CVSS severity alone may not reflect business impact, especially for cloud storage, where exposure and classification drive risk. Ranking by highest CVSS score regardless of classification or reachability is wrong because CVSS measures technical severity, not the cloud-specific consequence of leaking sensitive data. Ranking by the largest number of affected cloud resources before assessing sensitivity is wrong because sprawl can overprioritize low-impact findings while ignoring a small but critical data leak. Ranking by the fastest automated remediation before confirming public exposure is wrong because remediation speed is not a risk metric; unconfirmed exposure can be misclassified, private, or low sensitivity. Exam caveat: On CS0-004, choose the prioritization method that ties vulnerability severity to business impact, especially data sensitivity and public reachability, rather than relying on scanner scores alone. Operational check: Confirm whether each storage bucket is publicly accessible, identify the data classification, then rank findings by regulated data exposure before assigning remediation work.