Courseiva
Vulnerability Management →easyMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing the results of a vulnerability scan. The analyst sees a plugin output that includes the CVSS vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. What is the base score of this vulnerability?

⚠ Common exam trap

CS0-004 often tests the Scope metric — candidates see all-High impacts and pick 10.0, forgetting that 10.0 requires S:C (Changed), while S:U caps the score at 9.8.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

9.8

The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a network-exploitable vulnerability with low attack complexity, no privileges or user interaction required, unchanged scope, and high impact to confidentiality, integrity, and availability. This combination yields a base score of 9.8 (Critical), the maximum for an unchanged-scope vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    6.5

    Why it's wrong here

    A CVSS v3.1 score of 6.5 represents a Medium-severity vulnerability. This score would typically result from a vector with significantly restricted metrics, such as requiring local access (AV:L) or high privileges (PR:H), which does not align with the maximum-impact, zero-privilege network vector provided here.

  • ✓

    9.8

    Why this is correct

    The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a worst-case scenario where an unauthenticated remote attacker can fully compromise confidentiality, integrity, and availability without user interaction. Because the Scope is Unchanged (S:U), the mathematical formula caps the maximum possible base score at 9.8 rather than 10.0.

  • ✗

    10.0

    Why it's wrong here

    A perfect CVSS score of 10.0 is mathematically impossible when the Scope metric is Unchanged (S:U). To reach a 10.0 rating, the vulnerability must involve a Scope Change (S:C) alongside maximum impact metrics (C:H/I:H/A:H), allowing the exploit to impact resources outside the security authority of the vulnerable component.

  • ✗

    7.5

    Why it's wrong here

    A score of 7.5 is classified as High severity but is too low for this specific vector. This score would occur if the vector contained mitigating factors, such as requiring High Privileges (PR:H) or User Interaction (UI:R), which are absent in this fully remote, zero-interaction exploit vector.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.