Courseiva
Vulnerability ManagementmediumMultiple SelectObjective-mapped

CS0-003 Vulnerability Management Practice Question

A security analyst is using OpenVAS to scan a network. The scan identifies several vulnerabilities. Which TWO of the following are valid components of a CVSS v3.1 base score? (Select the two correct answers.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Scope (S)

Attack Vector and Scope are both part of the CVSS v3.1 base score.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Exploitability (E)

    Why it's wrong here

    Exploitability (E) is not a base metric; it belongs to the temporal metric group in CVSS v3.1. Temporal metrics assess the current state of exploit techniques or code availability, which can change over time. Since OpenVAS typically provides a base score reflecting intrinsic vulnerability characteristics, Exploitability is not part of the base metric set and is therefore incorrect.

  • Confidence (C)

    Why it's wrong here

    Confidence (C) is an environmental metric in CVSS v3.1, not a base metric. It represents the degree of certainty about the existence of the vulnerability and the credibility of the report, which depends on external validation. Base metrics are intrinsic and independent of such confirmation, so Confidence is not a valid choice for a base metric.

  • Remediation Level (RL)

    Why it's wrong here

    Remediation Level (RL) is a temporal metric that describes the availability of a fix or workaround, such as an official fix, temporary fix, or unavailable. It is not a base metric because base metrics are immutable characteristics of the vulnerability, unaffected by time or vendor responses. Therefore, RL does not belong in the base metric group and is incorrect.

  • Scope (S)

    Why this is correct

    Scope (S) is a correct base metric in CVSS v3.1, measuring whether a vulnerability in one vulnerable component can impact resources beyond its security scope. A changed scope indicates that exploitation may affect other components, increasing the overall severity. OpenVAS includes Scope in the base vector, so it is a valid base metric.

  • Attack Vector (AV)

    Why this is correct

    Attack Vector (AV) is a base metric in CVSS v3.1 that reflects the context by which a vulnerability can be exploited, such as network, adjacent, local, or physical. It is an inherent characteristic of the vulnerability and is always included in the base score calculation, regardless of time or environment. Thus, Attack Vector is a correct base metric.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.