How should vulnerabilities be prioritised beyond severity score?
- A By exploitability and exposure, such as internet-facing systems with public exploits
- B By alphabetical order of the software
- C By the size of the patch
- D By the age of the CVE
Answer
By exploitability and exposure, such as internet-facing systems with public exploits
A critical score in software you do not run is noise. Asset inventory is what makes meaningful triage possible.





