A vulnerability on a jump host used by administrators to reach production servers scores CVSS 8.1. The host has no internet exposure, but it stores SSH keys and administrative credentials for many systems. Which prioritization rationale best fits the risk?
Select an answer to reveal the explanation.
Short Explanation
Think of a jump host like a master key ring: one broken lock can open many doors. You don’t just score the lock; you ask how much of the building it unlocks. That blast radius is what should push this finding up the queue.
Full Explanation
Vulnerability prioritization should combine technical severity with exposure, privilege, and downstream reachability. A jump host is an access-control chokepoint: if it is compromised, an adversary may obtain administrative credentials, SSH keys, or session data that permit lateral movement to many production systems. That increased blast radius can justify elevating a finding even when the base score is moderate or the host is not directly exposed to untrusted networks. Treating the issue as low priority solely because the vulnerable component exists on one system ignores that one system can be the gateway to many others. Waiting for a routine patch cycle based only on a numeric threshold also misses the operational significance of privileged access paths. Relying on the absence of observed exploitation is a monitoring signal, not a risk assessment, because vulnerabilities may be exploited later or by attackers with internal access. Exam caveat: do not let CVSS, scanner confidence, or lack of internet exposure override business and access context. Operational check: inventory privileged accounts and credentials stored on the jump host, enumerate reachable critical systems, and validate emergency patch or network isolation options.