CS0-003 Vulnerability Management Practice Question
During a vulnerability scan, an analyst identifies a plugin that reports a vulnerability with a CVSS v3.1 base score of 7.5. The vector string includes AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Which of the following is the primary impact of this vulnerability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Availability
The CIA impact ratings show A:H (Availability High), meaning the vulnerability primarily impacts availability. C:N and I:N indicate no impact on confidentiality or integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Integrity
Why it's wrong here
The vector's Integrity component is I:N, meaning None, which means this vulnerability grants an attacker no ability to modify data or system state. Integrity is explicitly ruled out as an impact, so it cannot be the primary consequence the question is asking about.
- ✗
Scope change
Why it's wrong here
Scope is a CVSS metric describing whether an exploited vulnerability can affect resources beyond its own security scope, and this vector shows S:U, meaning Unchanged, so the impact stays confined to the vulnerable component; furthermore, scope is a metric dimension, not one of the three CIA impact categories the question is asking about.
- ✓
Availability
Why this is correct
The vector's Availability metric is A:H, meaning High, the only impact metric set above None in this string, indicating the vulnerability can fully deny access to the affected resource, for example through a crash or resource exhaustion condition, making Availability the clear primary impact and consistent with a 7.5 base score driven almost entirely by this single high-impact metric.
- ✗
Confidentiality
Why it's wrong here
The vector's Confidentiality metric is C:N, meaning None, indicating the vulnerability provides no unauthorized access to data. Since both Confidentiality and Integrity are explicitly None in this string, only Availability remains as the affected property, ruling this option out directly from the vector string itself.
Go deeper
Related to this question
Learn chapter
Risk Register and Vulnerability Register
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.