CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing a vulnerability scan report and notices a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and the scope impact?
⚠ Common exam trap
CS0-004 often tests CVSS vector decoding — candidates confuse AV:N with AV:A or misread S:U as S:C, especially when the high 9.8 score suggests 'changed scope' intuitively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attack vector: Network; Scope: Unchanged
The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H decodes as Attack Vector: Network (AV:N) and Scope: Unchanged (S:U). AV:N means the vulnerability is exploitable remotely over a network, and S:U means a successful exploit affects only the vulnerable component's security authority, not other components. The 9.8 base score is consistent with a network-exploitable, no-privilege, no-interaction, high-impact vulnerability with unchanged scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attack vector: Network; Scope: Unchanged
Why this is correct
Correct. AV:N indicates the vulnerability is exploitable remotely over a network without requiring physical or adjacent access, and S:U means the exploited component's impact stays confined within its own security scope rather than affecting resources managed by a different authority.
- ✗
Attack vector: Network; Scope: Changed
Why it's wrong here
The attack vector is correctly identified as network, but the scope metric in the vector string reads S:U, which stands for Unchanged; a Changed scope would only apply if exploitation let the attacker impact a component beyond the vulnerable one's own security authority.
- ✗
Attack vector: Local; Scope: Changed
Why it's wrong here
This option misreads two separate metrics: AC:L in the vector refers to Attack Complexity being Low, not the attack vector, and the actual AV value is N for Network; additionally scope is Unchanged (S:U), not Changed, making both halves of this answer incorrect.
- ✗
Attack vector: Adjacent; Scope: Unchanged
Why it's wrong here
Adjacent (AV:A) would mean the attacker must be on the same physical or logical network segment, such as the same Bluetooth or Wi-Fi range, but the vector string explicitly shows AV:N for network-based exploitation reachable across routed networks, not a proximity-limited adjacent vector.
Go deeper
Related to this question
Learn chapter
Splunk SPL Queries for Security Analysts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.