Courseiva
Vulnerability Management →easyMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing vulnerability scan results and notices that a critical vulnerability on a web server has a CVSS v3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of the CVSS vector indicates that the vulnerability can be exploited from a remote network?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AV:N

AV stands for Attack Vector. AV:N means the vulnerability is exploitable over a network, indicating remote exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PR:N

    Why it's wrong here

    The Privileges Required (PR) metric describes the level of authorization an attacker must possess before successfully exploiting the vulnerability. A value of PR:N (None) indicates that an unauthenticated attacker can execute the exploit, but this metric does not define the physical or logical path, such as network reachability, required to reach the target system.

  • ✓

    AV:N

    Why this is correct

    The Attack Vector (AV) metric represents the context in which vulnerability exploitation is possible. A value of AV:N (Network) explicitly indicates that the vulnerability is exploitable remotely over the network, meaning the attacker does not need local, physical, or adjacent network access to compromise the target.

  • ✗

    AC:L

    Why it's wrong here

    Attack Complexity (AC) measures the conditions beyond the attacker's control that must exist in order to exploit the vulnerability. While AC:L (Low) signifies that the exploit can be executed consistently and easily without specialized conditions, it does not provide information regarding the network vector or remote accessibility of the vulnerable service.

  • ✗

    UI:N

    Why it's wrong here

    The User Interaction (UI) metric determines whether a human user must participate in some way, such as clicking a link or opening a file, for the exploit to succeed. Although UI:N (None) means the vulnerability can be exploited silently without any victim interaction, it remains entirely independent of the network reachability or attack vector requirements.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.