A SOC analyst sees a CVSS 9.8 vulnerability on an internet-facing web server and a CVSS 7.4 vulnerability on the payroll database. The payroll system supports monthly employee payments and has no compensating controls. Which vulnerability should the analyst recommend remediating first?
Select an answer to reveal the explanation.
Short Explanation
Think of CVSS as a fire alarm, not a building blueprint. It doesn't tell you whether the burning room is the payroll office or a less critical web server. You remediate where business impact turns a technical score into real operational risk.
Full Explanation
Vulnerability response should combine technical severity with business impact analysis. CVSS describes exploitability and potential damage, but it does not know which asset is essential to operations. A payroll system that enables employee payments has high availability and integrity requirements; disruption can cause missed payments, compliance exposure, and employee trust damage. Therefore, a lower CVSS item on that asset can outrank a higher CVSS item on a less critical web server, especially when compensating controls are absent. Internet exposure is important, but it does not automatically make an asset the first remediation target; the analyst must weigh exposure, asset value, exploitability, and existing mitigations. CVSS severity is a starting point, not the sole remediation driver. Financial sensitivity alone does not prove one asset is always more important than another; business impact analysis determines the actual operational consequence. In practice, map the asset to business services, estimate downtime or data-integrity consequences, and use that impact to order remediation tickets. Exam caveat: Do not choose the highest CVSS score when the stem supplies business impact facts that change operational risk. Operational check: Rank the vulnerabilities by asking which failure causes the largest measurable disruption to payroll processing, payments, regulatory obligations, or recovery cost.