A vulnerability scanner reports a critical CVSS 9.8 on an isolated test server and a medium CVSS 6.1 on an internet-facing web application that stores customer records. The business owner asks why the critical finding is not automatically the highest priority. Which statement best explains why CVSS severity alone does not equal organizational risk?
Select an answer to reveal the explanation.
Short Explanation
Think of CVSS like a weather report: it tells you how bad the storm is, not whether your house is in its path. You still need to know what's exposed, what's on it, and how much it hurts if it goes down. That's why a critical score on an isolated box doesn't outrank a medium score on a customer-facing app.
Full Explanation
CVSS base severity expresses intrinsic technical severity under standard assumptions. It helps compare flaws, but organizational risk requires adding context: service exposure, authentication requirements, asset criticality, data sensitivity, and likelihood of exploitation. Vulnerability management reporting should translate technical severity into a business-facing risk statement so owners can compare remediation effort against potential loss. The statement that CVSS already accounts for internet exposure is wrong because base metrics do not include asset value, network location, or compensating controls. Environmental metrics can reflect context, but they are not automatically applied by a scanner's default base score. The claim that patch availability determines risk is wrong because absent or delayed patches do not reduce exposure; they may increase operational risk until compensating controls are applied. The claim that business impact cannot be quantified is wrong because organizations can estimate impact through data classification, service criticality, revenue dependency, downtime cost, and regulatory consequence. Exam caveat: CompTIA expects you to distinguish CVSS technical severity from risk, which is likelihood times impact. Operational check: Map critical findings to asset owner, exposure, data sensitivity, and controls before assigning priority.