Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing a vulnerability scan report and finds a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and impact of this vulnerability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network attack vector, high impact on confidentiality, integrity, and availability

AV:N indicates network-based attack vector, meaning the vulnerability can be exploited remotely over the network. The CIA impact ratings are all High, indicating complete compromise of confidentiality, integrity, and availability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adjacent attack vector, high impact on availability only

    Why it's wrong here

    This option incorrectly identifies the Attack Vector as Adjacent, which would require the attacker to share a physical or logical network segment like a local subnet. Furthermore, it erroneously limits the high impact to availability alone, failing to account for the high impact across all three pillars of the CIA triad.

  • ✓

    Network attack vector, high impact on confidentiality, integrity, and availability

    Why this is correct

    This option accurately reflects a CVSS v3 vector string where the Attack Vector is Network, meaning the vulnerability can be exploited remotely over the internet. It also correctly identifies that the exploit results in a High impact rating for confidentiality, integrity, and availability, indicating total compromise of the affected system.

  • ✗

    Physical attack vector, medium impact on confidentiality

    Why it's wrong here

    This choice is incorrect because a physical attack vector requires the threat actor to have physical access to the target hardware, which is not indicated. Additionally, CVSS v3 does not use a "Medium" rating for confidentiality impact; it categorizes impact strictly as None, Low, or High.

  • ✗

    Local attack vector, low impact on confidentiality

    Why it's wrong here

    A local attack vector requires the attacker to have direct console access, local shell access, or rely on user interaction to execute the exploit. It also incorrectly downplays the severity of the compromise by designating confidentiality impact as low rather than high.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.