Study. uk . com
  1. Home
  2. All questions
  3. Question 179

CompTIA Security+ study material · question 179 of 611

A team patches every critical-severity finding first, regardless of whether the affected service is reachable. What is the problem with this policy?

  1. Critical findings should always be patched last
  2. It conflicts with the change advisory board's authority
  3. It ignores exposure and exploitation evidence, wasting the scarce maintenance window
  4. Severity is not a valid prioritisation input
Show the answer

Answer: C. It ignores exposure and exploitation evidence, wasting the scarce maintenance window

Prioritisation should combine severity with reachability and evidence of active exploitation.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.2 Software Vulnerability Management Life Cycle

Challenge yourself on this topic → Study as cards