CS0-003 Vulnerability Management Practice Question
During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is network, attack complexity is low, privileges required are none, user interaction is none, and the impact to confidentiality, integrity, and availability is high. Which CVSS vector string represents this vulnerability?
⚠ Common exam trap
CS0-004 often tests the ability to map a description to the correct CVSS vector; candidates may confuse AC:L with AC:H or PR:N with PR:L, so they must read the description carefully.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a vulnerability with network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and high impact to confidentiality, integrity, and availability. This matches the description and yields a base score of 9.8 (Critical).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Why this is correct
Every metric matches the scenario exactly: AV:N reflects remote network exploitability, AC:L means no special conditions are needed, PR:N and UI:N confirm no authentication or victim action is required, and C:H/I:H/A:H capture the total loss of confidentiality, integrity, and availability, which together drive the 9.8 critical base score.
- ✗
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Why it's wrong here
Setting AC:H instead of AC:L wrongly implies the attacker must wait for specific configuration or timing conditions outside their control before exploitation succeeds, which contradicts the scenario's explicit statement of low attack complexity and would also pull the base score below 9.8.
- ✗
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Why it's wrong here
Using PR:L instead of PR:N incorrectly implies the attacker needs a valid low-privileged account on the target before launching the exploit, whereas the scenario specifies privileges required as none, meaning any unauthenticated remote actor can exploit it directly.
- ✗
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Why it's wrong here
AV:A limits the attacker to the same physical or logical network segment, such as a shared Wi-Fi or Bluetooth range, which understates the exposure described; the scenario specifies AV:N, meaning the vulnerability is reachable from anywhere on the internet without proximity to the target.
Go deeper
Related to this question
Learn chapter
SOC Tier 1, Tier 2, and Tier 3 Analyst Roles
Key term
Attack vector
An attack vector is the specific path or method a cyber attacker uses to gain unauthorized access to a computer system or network.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.