高度に悪用された 2 つの脆弱性に対するパッチが、同じ金曜日の午後にリリースされました。システムと脆弱性に関する情報を以下の表に示します。

セキュリティ アナリストは修復のために次のどれを優先する必要がありますか?
正解:B
Brady should be prioritized for remediation, as it has the highest risk score and the highest number of affected users. The risk score is calculated by multiplying the CVSS score by the exposure factor, which is the percentage of systems that are vulnerable to the exploit. Brady has a risk score of 9 x 0.8 = 7.2, which is higher than any other system. Brady also has 500 affected users, which is more than any other system. Therefore, patching brady would reduce the most risk and impact for the organization. The other systems have lower risk scores and lower numbers of affected users, so they can be remediated later.