A vulnerability analyst triages findings in a hybrid SOC. Some systems have higher business value and exposure. Leadership has approved a risk appetite statement for acceptable exposure. What primarily determines how quickly a vulnerability finding must be remediated?
Select an answer to reveal the explanation.
Short Explanation
Think of risk appetite like a speed limit: your org decides how much exposure is tolerable, then you drive your remediation SLAs to match. CVSS and scanner severities help rank findings, but they don't set the speed limit for your business. You need leadership-approved appetite to know when 'urgent' is actually urgent.
Full Explanation
Risk appetite is the organization's formal tolerance for uncertainty and potential loss, so it is the governance input that translates technical findings into response expectations. In vulnerability management, it determines acceptable residual risk and therefore how quickly findings must be treated, especially when assets differ in business criticality, exposure, or compensating controls. A high-risk appetite may allow slower remediation for low-criticality systems, while a low-risk appetite can force accelerated action even for findings that look moderate on a scanner. The CVSS base score is useful for intrinsic severity, but it does not reflect organizational exposure, business value, or acceptable risk by itself. The asset owner's tolerance can inform the process, yet it is not the authoritative enterprise standard unless it is incorporated into approved risk governance. The scanner's severity rating reflects product-specific classification and may be incomplete without asset context or organizational risk criteria. Exam caveat: CompTIA often expects risk appetite, not CVSS or scanner severity, to drive remediation urgency when both are present. Operational check: Map each finding to an asset criticality tier and the approved remediation SLA derived from the organization's risk appetite.