CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing a vulnerability scan report and sees a finding for a web application with a CVSS v3.1 base score of 6.1. The vector string is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. Which OWASP Top 10 category does this vulnerability most likely belong to?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A03: Injection
The vector indicates Reflected XSS (requires user interaction, scope change, low CIA impact). Reflected XSS is part of the OWASP Top 10 category 'Injection' (2017) or 'Cross-site Scripting' (2021). However, the most direct is Cross-site Scripting (XSS).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A03: Injection
Why this is correct
In the OWASP Top 10:2021 framework, Cross-Site Scripting (XSS) has been consolidated into the A03: Injection category. Reflected XSS occurs when untrusted user input is dynamically injected into a web application's response without proper sanitization or encoding. Consequently, a vulnerability scan identifying a reflected XSS vulnerability with a CVSS vector indicating user interaction and scope change directly maps to this category.
- ✗
A05: Security Misconfiguration
Why it's wrong here
Security misconfigurations typically involve default accounts, unencrypted services, or overly permissive CORS headers, which do not inherently require user interaction or trigger a CVSS scope change. In contrast, reflected XSS relies on a victim actively clicking a malicious link (User Interaction: Required) to execute script in the context of their browser session, altering the security scope. Therefore, this category is incorrect for a standard XSS finding.
- ✗
A06: Vulnerable and Outdated Components
Why it's wrong here
This category applies when an application uses third-party libraries or frameworks with known, unpatched CVEs, which typically carry CVSS vectors reflecting direct system compromise or remote code execution. While a vulnerable component could theoretically contain an XSS flaw, a standard custom-code reflected XSS vulnerability is classified under injection rather than outdated software. The CVSS vector for outdated components usually lacks the specific scope-change and user-interaction requirements characteristic of reflected XSS.
- ✗
A01: Broken Access Control
Why it's wrong here
Broken access control vulnerabilities occur when an application fails to properly enforce authorization boundaries, allowing users to access unauthorized resources or perform privileged actions. This category typically involves IDOR, path traversal, or privilege escalation, which do not rely on injecting executable scripts into a user's browser session. While an attacker might leverage XSS to steal session tokens and subsequently bypass access controls, the root vulnerability of reflected XSS itself is classified under injection.
Go deeper
Related to this question
Learn chapter
Security Metrics and KPIs
Key term
OWASP Top 10
The OWASP Top 10 is a regularly updated list of the most critical security risks to web applications, published by the Open Web Application Security Project (OWASP) to help developers and security professionals prioritize and mitigate common vulnerabilities.
Key term
Cross-site scripting
Cross-site scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users, often to steal data or hijack sessions.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.