Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing a vulnerability scan report and sees a finding for a web application with a CVSS v3.1 base score of 6.1. The vector string is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. Which OWASP Top 10 category does this vulnerability most likely belong to?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A03: Injection

The vector indicates Reflected XSS (requires user interaction, scope change, low CIA impact). Reflected XSS is part of the OWASP Top 10 category 'Injection' (2017) or 'Cross-site Scripting' (2021). However, the most direct is Cross-site Scripting (XSS).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A03: Injection

    Why this is correct

    In the OWASP Top 10:2021 framework, Cross-Site Scripting (XSS) has been consolidated into the A03: Injection category. Reflected XSS occurs when untrusted user input is dynamically injected into a web application's response without proper sanitization or encoding. Consequently, a vulnerability scan identifying a reflected XSS vulnerability with a CVSS vector indicating user interaction and scope change directly maps to this category.

  • ✗

    A05: Security Misconfiguration

    Why it's wrong here

    Security misconfigurations typically involve default accounts, unencrypted services, or overly permissive CORS headers, which do not inherently require user interaction or trigger a CVSS scope change. In contrast, reflected XSS relies on a victim actively clicking a malicious link (User Interaction: Required) to execute script in the context of their browser session, altering the security scope. Therefore, this category is incorrect for a standard XSS finding.

  • ✗

    A06: Vulnerable and Outdated Components

    Why it's wrong here

    This category applies when an application uses third-party libraries or frameworks with known, unpatched CVEs, which typically carry CVSS vectors reflecting direct system compromise or remote code execution. While a vulnerable component could theoretically contain an XSS flaw, a standard custom-code reflected XSS vulnerability is classified under injection rather than outdated software. The CVSS vector for outdated components usually lacks the specific scope-change and user-interaction requirements characteristic of reflected XSS.

  • ✗

    A01: Broken Access Control

    Why it's wrong here

    Broken access control vulnerabilities occur when an application fails to properly enforce authorization boundaries, allowing users to access unauthorized resources or perform privileged actions. This category typically involves IDOR, path traversal, or privilege escalation, which do not rely on injecting executable scripts into a user's browser session. While an attacker might leverage XSS to steal session tokens and subsequently bypass access controls, the root vulnerability of reflected XSS itself is classified under injection.

Go deeper

Related to this question

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.