Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

During a vulnerability scan, an analyst identifies a plugin that reports a vulnerability with a CVSS v3.1 base score of 7.5. The vector string includes AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Which of the following is the primary impact of this vulnerability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Availability

The CIA impact ratings show A:H (Availability High), meaning the vulnerability primarily impacts availability. C:N and I:N indicate no impact on confidentiality or integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Integrity

    Why it's wrong here

    The vector's Integrity component is I:N, meaning None, which means this vulnerability grants an attacker no ability to modify data or system state. Integrity is explicitly ruled out as an impact, so it cannot be the primary consequence the question is asking about.

  • ✗

    Scope change

    Why it's wrong here

    Scope is a CVSS metric describing whether an exploited vulnerability can affect resources beyond its own security scope, and this vector shows S:U, meaning Unchanged, so the impact stays confined to the vulnerable component; furthermore, scope is a metric dimension, not one of the three CIA impact categories the question is asking about.

  • ✓

    Availability

    Why this is correct

    The vector's Availability metric is A:H, meaning High, the only impact metric set above None in this string, indicating the vulnerability can fully deny access to the affected resource, for example through a crash or resource exhaustion condition, making Availability the clear primary impact and consistent with a 7.5 base score driven almost entirely by this single high-impact metric.

  • ✗

    Confidentiality

    Why it's wrong here

    The vector's Confidentiality metric is C:N, meaning None, indicating the vulnerability provides no unauthorized access to data. Since both Confidentiality and Integrity are explicitly None in this string, only Availability remains as the affected property, ruling this option out directly from the vector string itself.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.