Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is evaluating a vulnerability with CVSS v3.1 base score: AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N. Which of the following best describes the scope and impact of this vulnerability?

⚠ Common exam trap

CS0-004 often tests precise CVSS vector parsing, so candidates who skim the string and assume multiple impacts or unchanged scope (because only one impact is High) select the wrong description.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scope is changed, high impact on confidentiality only

The CVSS v3.1 vector AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N indicates Scope is Changed (S:C) and Confidentiality impact is High (C:H), while Integrity (I:N) and Availability (A:N) impacts are None. Therefore, the correct description is scope changed with high impact on confidentiality only. The other options misstate either the scope or the impacted security property.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scope is unchanged, high impact on confidentiality only

    Why it's wrong here

    This choice misidentifies the Scope metric: the CVSS vector expresses S:C (Scope Changed), meaning the vulnerability can affect resources beyond the security authority of the vulnerable component. An Unchanged scope would mean impact is confined to that component, but S:C requires evaluating confidentiality relative to the broader impacted system. Thus, while C:H is correct, the scope assertion makes this answer wrong.

  • ✗

    Scope is changed, high impact on integrity only

    Why it's wrong here

    This answer incorrectly elevates integrity impact to H; the vector shows I:N, indicating no loss of integrity or data authenticity. The vulnerable component's failure does not allow modification, and only confidentiality is rated high (C:H). Although S:C is accurately stated, claiming I:H conflicts directly with the CVSS vector and cannot be accepted.

  • ✗

    Scope is unchanged, high impact on confidentiality and integrity

    Why it's wrong here

    This option contains two errors: it both rejects the correct Scope finding and fabricates an integrity impact. Scope is Changed (S:C), not Unchanged, because the compromise can propagate beyond the component's security boundary. Also, integrity is None (I:N), with no evidence of data alteration, so pairing high confidentiality and integrity with unchanged scope is doubly inconsistent with the vector.

  • ✓

    Scope is changed, high impact on confidentiality only

    Why this is correct

    This is correct: the vector specifies S:C (Scope Changed) and C:H (high confidentiality impact), while integrity and availability are None (I:N/A:N). A Changed scope means the vulnerability affects resources outside the vulnerable component's security authority, and the only rated impact is disclosure of sensitive information. These values exactly match the analyst's finding.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.