CS0-003 Vulnerability Management Practice Question
A security analyst is using OpenVAS to scan a network. The scan identifies several vulnerabilities. Which TWO of the following are valid components of a CVSS v3.1 base score? (Select the two correct answers.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scope (S)
Attack Vector and Scope are both part of the CVSS v3.1 base score.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploitability (E)
Why it's wrong here
Exploitability (E) is not a base metric; it belongs to the temporal metric group in CVSS v3.1. Temporal metrics assess the current state of exploit techniques or code availability, which can change over time. Since OpenVAS typically provides a base score reflecting intrinsic vulnerability characteristics, Exploitability is not part of the base metric set and is therefore incorrect.
- ✗
Confidence (C)
Why it's wrong here
Confidence (C) is an environmental metric in CVSS v3.1, not a base metric. It represents the degree of certainty about the existence of the vulnerability and the credibility of the report, which depends on external validation. Base metrics are intrinsic and independent of such confirmation, so Confidence is not a valid choice for a base metric.
- ✗
Remediation Level (RL)
Why it's wrong here
Remediation Level (RL) is a temporal metric that describes the availability of a fix or workaround, such as an official fix, temporary fix, or unavailable. It is not a base metric because base metrics are immutable characteristics of the vulnerability, unaffected by time or vendor responses. Therefore, RL does not belong in the base metric group and is incorrect.
- ✓
Scope (S)
Why this is correct
Scope (S) is a correct base metric in CVSS v3.1, measuring whether a vulnerability in one vulnerable component can impact resources beyond its security scope. A changed scope indicates that exploitation may affect other components, increasing the overall severity. OpenVAS includes Scope in the base vector, so it is a valid base metric.
- ✓
Attack Vector (AV)
Why this is correct
Attack Vector (AV) is a base metric in CVSS v3.1 that reflects the context by which a vulnerability can be exploited, such as network, adjacent, local, or physical. It is an inherent characteristic of the vulnerability and is always included in the base score calculation, regardless of time or environment. Thus, Attack Vector is a correct base metric.
Go deeper
Related to this question
Learn chapter
Network Traffic Analysis
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
Key term
Attack vector
An attack vector is the specific path or method a cyber attacker uses to gain unauthorized access to a computer system or network.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.