A vulnerability scan produces two image reports: high-severity CVEs in images used by running production workloads and high-severity CVEs in build-time images not yet deployed. The CISO asks which remediation queue should be communicated first to reduce risk. Which prioritization is best?
Select an answer to reveal the explanation.
Short Explanation
Think of it like patching a leak: you fix the pipe already under pressure, not the one sitting in the warehouse. Tell your stakeholders to clear running production images first, because actual exposure drives urgency. Build-time findings still matter, but they don't carry the same immediate blast radius.
Full Explanation
Vulnerability reporting should translate scan data into remediation urgency that matches real-world exposure. A running production container image is already deployed, can be reachable by workloads, and may be exploited immediately, so a high-severity finding in that image deserves the highest communicated priority. Build-time images, even with high CVSS scores, represent latent risk until they are promoted, so they are important but not the same immediate exposure. Treating every high-severity image equally ignores deployment state and can push scarce remediation effort toward undeployed artifacts while live systems remain exposed. Prioritizing build-time images because they can stop future promotions addresses prevention, not current risk; it may delay fixes for systems already in production. Prioritizing registry-cached images because they are easier to patch confuses operational convenience with risk reduction; ease of remediation should sequence work within a priority tier, not define the priority tier itself. Exam caveat: CompTIA often tests whether you communicate urgency from actual exposure and business impact, not just CVSS labels or scanning ease. Operational check: filter the scan output for running production images, confirm image tags, host reachability, and network exposure, then issue a remediation list ordered by deployed high-severity findings with SLA dates.