Courseiva
hardMultiple Choice

CS0-003 Practice Question: Based on the scan output, which vulnerability…

Network Topology
$ nmap -sVscript vulnersRefer to the exhibit.Nmap scan report for 10.0.1.50Host is up (0.0012s latency).PORT STATE SERVICE VERSION| vulners:| cpe:/a:openbsd:openssh:8.0:| CVE-2020-15778 9.8 https://vulners.com/cve/CVE-2020-15778| CVE-2019-16905 7.5 https://vulners.com/cve/CVE-2019-16905|_ CVE-2020-12060 5.3 https://vulners.com/cve/CVE-2020-12060

Based on the scan output, which vulnerability should be prioritized first for remediation?

⚠ Common exam trap

CompTIA often tests the principle that remote code execution (RCE) vulnerabilities with no authentication requirement should always be prioritized over local privilege escalation or denial-of-service vulnerabilities, even if the latter have higher CVSS scores in some categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CVE-2020-15778

CVE-2020-15778 is a critical command injection vulnerability in OpenSSH's scp utility that allows an unauthenticated remote attacker to execute arbitrary commands on the target system by crafting a malicious scp source path. This vulnerability has a CVSS score of 9.8 (Critical) and is remotely exploitable without authentication, making it the highest priority for remediation over the other listed CVEs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CVE-2019-16905

    Why it's wrong here

    CVSS 7.5, lower priority.

  • ✓

    CVE-2020-15778

    Why this is correct

    Highest CVSS score (9.8).

  • ✗

    CVE-2020-12060

    Why it's wrong here

    CVSS 5.3, lowest priority.

  • ✗

    Both A and B equally.

    Why it's wrong here

    This is incorrect because the vulnerabilities are not equally prioritized; CVE-2020-15778 (B) is more critical due to remote code execution without authentication, so both should not be treated equally.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.