CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing a vulnerability scan report and finds a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and impact of this vulnerability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network attack vector, high impact on confidentiality, integrity, and availability
AV:N indicates network-based attack vector, meaning the vulnerability can be exploited remotely over the network. The CIA impact ratings are all High, indicating complete compromise of confidentiality, integrity, and availability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Adjacent attack vector, high impact on availability only
Why it's wrong here
This option incorrectly identifies the Attack Vector as Adjacent, which would require the attacker to share a physical or logical network segment like a local subnet. Furthermore, it erroneously limits the high impact to availability alone, failing to account for the high impact across all three pillars of the CIA triad.
- ✓
Network attack vector, high impact on confidentiality, integrity, and availability
Why this is correct
This option accurately reflects a CVSS v3 vector string where the Attack Vector is Network, meaning the vulnerability can be exploited remotely over the internet. It also correctly identifies that the exploit results in a High impact rating for confidentiality, integrity, and availability, indicating total compromise of the affected system.
- ✗
Physical attack vector, medium impact on confidentiality
Why it's wrong here
This choice is incorrect because a physical attack vector requires the threat actor to have physical access to the target hardware, which is not indicated. Additionally, CVSS v3 does not use a "Medium" rating for confidentiality impact; it categorizes impact strictly as None, Low, or High.
- ✗
Local attack vector, low impact on confidentiality
Why it's wrong here
A local attack vector requires the attacker to have direct console access, local shell access, or rely on user interaction to execute the exploit. It also incorrectly downplays the severity of the compromise by designating confidentiality impact as low rather than high.
Go deeper
Related to this question
Learn chapter
CVE, CVSS, and EPSS Scoring
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.