CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing a vulnerability scan report from Rapid7 InsightVM. The report shows that a Tomcat server has a plugin finding indicating that the 'Server' header is set to 'Apache-Coyote/1.1', which reveals the server version. Which type of vulnerability does this represent?
⚠ Common exam trap
CS0-004 often tests the classification of information disclosure as a security misconfiguration, where candidates might incorrectly label it as broken access control or injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security misconfiguration
The 'Server' header revealing the server version is a security misconfiguration because it exposes unnecessary information that could aid attackers in targeting known vulnerabilities. This falls under the OWASP Top 10 category of Security Misconfiguration. It is not a direct vulnerability but a configuration weakness that should be remediated by suppressing version details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Broken access control
Why it's wrong here
While broken access control flaws allow unauthorized users to bypass authorization checks, access restricted resources, or escalate privileges, they do not describe the passive exposure of system metadata. This finding is a passive information disclosure rather than a failure to enforce user permissions or object-level authorization boundaries.
- ✗
Injection vulnerability
Why it's wrong here
Injection vulnerabilities occur when untrusted user input is directly interpreted as code or queries by an interpreter, such as in SQL injection or cross-site scripting. Revealing a server version banner does not involve malicious input execution or command interpretation, making this classification incorrect for a simple information disclosure finding.
- ✓
Security misconfiguration
Why this is correct
Exposing detailed server version banners is a classic security misconfiguration that leaks valuable reconnaissance data to potential attackers. By failing to disable verbose headers or default error pages, administrators inadvertently assist adversaries in mapping out specific, exploitable vulnerabilities associated with that software version.
- ✗
Cryptographic failure
Why it's wrong here
Cryptographic failures stem from the use of weak encryption algorithms, outdated protocols like TLS 1.0, or improper key management practices that compromise data confidentiality. Although exposing server versions is a security risk, it does not involve the failure of cryptographic operations, cipher suites, or data-at-rest protection mechanisms.
Go deeper
Related to this question
Learn chapter
Executive Security Reporting
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
OWASP Top 10
The OWASP Top 10 is a regularly updated list of the most critical security risks to web applications, published by the Open Web Application Security Project (OWASP) to help developers and security professionals prioritize and mitigate common vulnerabilities.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.