A Windows Server 2012 environment undergoes a vulnerability scan revealing 200 vulnerabilities. Which risk management approach should guide remediation prioritization?
-
A
Fix all vulnerabilities alphabetically by CVE ID
-
B
Prioritize by exploitability and potential business impact
-
C
Remediate newest vulnerabilities first regardless of severity
-
D
Address only vulnerabilities reported in news media