Courseiva
Vulnerability Management →easyMultiple Choice

CS0-003 Vulnerability Management Practice Question

During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is network, attack complexity is low, privileges required are none, user interaction is none, and the impact to confidentiality, integrity, and availability is high. Which CVSS vector string represents this vulnerability?

⚠ Common exam trap

CS0-004 often tests the ability to map a description to the correct CVSS vector; candidates may confuse AC:L with AC:H or PR:N with PR:L, so they must read the description carefully.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a vulnerability with network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and high impact to confidentiality, integrity, and availability. This matches the description and yields a base score of 9.8 (Critical).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

    Why this is correct

    Every metric matches the scenario exactly: AV:N reflects remote network exploitability, AC:L means no special conditions are needed, PR:N and UI:N confirm no authentication or victim action is required, and C:H/I:H/A:H capture the total loss of confidentiality, integrity, and availability, which together drive the 9.8 critical base score.

  • ✗

    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

    Why it's wrong here

    Setting AC:H instead of AC:L wrongly implies the attacker must wait for specific configuration or timing conditions outside their control before exploitation succeeds, which contradicts the scenario's explicit statement of low attack complexity and would also pull the base score below 9.8.

  • ✗

    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

    Why it's wrong here

    Using PR:L instead of PR:N incorrectly implies the attacker needs a valid low-privileged account on the target before launching the exploit, whereas the scenario specifies privileges required as none, meaning any unauthenticated remote actor can exploit it directly.

  • ✗

    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

    Why it's wrong here

    AV:A limits the attacker to the same physical or logical network segment, such as a shared Wi-Fi or Bluetooth range, which understates the exposure described; the scenario specifies AV:N, meaning the vulnerability is reachable from anywhere on the internet without proximity to the target.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.