Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing a vulnerability scan report from Rapid7 InsightVM. The report shows that a Tomcat server has a plugin finding indicating that the 'Server' header is set to 'Apache-Coyote/1.1', which reveals the server version. Which type of vulnerability does this represent?

⚠ Common exam trap

CS0-004 often tests the classification of information disclosure as a security misconfiguration, where candidates might incorrectly label it as broken access control or injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security misconfiguration

The 'Server' header revealing the server version is a security misconfiguration because it exposes unnecessary information that could aid attackers in targeting known vulnerabilities. This falls under the OWASP Top 10 category of Security Misconfiguration. It is not a direct vulnerability but a configuration weakness that should be remediated by suppressing version details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Broken access control

    Why it's wrong here

    While broken access control flaws allow unauthorized users to bypass authorization checks, access restricted resources, or escalate privileges, they do not describe the passive exposure of system metadata. This finding is a passive information disclosure rather than a failure to enforce user permissions or object-level authorization boundaries.

  • ✗

    Injection vulnerability

    Why it's wrong here

    Injection vulnerabilities occur when untrusted user input is directly interpreted as code or queries by an interpreter, such as in SQL injection or cross-site scripting. Revealing a server version banner does not involve malicious input execution or command interpretation, making this classification incorrect for a simple information disclosure finding.

  • ✓

    Security misconfiguration

    Why this is correct

    Exposing detailed server version banners is a classic security misconfiguration that leaks valuable reconnaissance data to potential attackers. By failing to disable verbose headers or default error pages, administrators inadvertently assist adversaries in mapping out specific, exploitable vulnerabilities associated with that software version.

  • ✗

    Cryptographic failure

    Why it's wrong here

    Cryptographic failures stem from the use of weak encryption algorithms, outdated protocols like TLS 1.0, or improper key management practices that compromise data confidentiality. Although exposing server versions is a security risk, it does not involve the failure of cryptographic operations, cipher suites, or data-at-rest protection mechanisms.

Go deeper

Related to this question

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.