Courseiva
Vulnerability Management →easyMultiple Choice

CS0-003 Vulnerability Management Practice Question

Which metric in the CVSS v3.1 base score indicates the level of access an attacker needs to exploit a vulnerability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileges Required (PR)

Privileges Required (PR) indicates the level of privileges an attacker must have before successfully exploiting the vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Privileges Required (PR)

    Why this is correct

    The Privileges Required (PR) metric measures the level of access privileges an attacker must possess prior to successfully exploiting the vulnerability. It is scored as None, Low, or High, directly reflecting whether the exploit requires administrative control, standard user access, or no authentication at all.

  • ✗

    Attack Vector (AV)

    Why it's wrong here

    The Attack Vector (AV) metric represents the physical or logical context through which an attacker can access the vulnerable system. It categorizes the exploit path based on proximity, ranging from Network (remote) to Physical, rather than assessing the authorization level or credentials required by the threat actor.

  • ✗

    Attack Complexity (AC)

    Why it's wrong here

    Attack Complexity (AC) evaluates the environmental conditions or specialized configurations outside of the attacker's direct control that must exist for the exploit to succeed. This metric focuses on factors like race conditions or specific system states, rather than the privilege level or credentials of the executing security principal.

  • ✗

    User Interaction (UI)

    Why it's wrong here

    The User Interaction (UI) metric determines whether a human user, other than the attacker, must actively participate or execute an action for the vulnerability to be successfully exploited. It is rated as None or Required, distinguishing automated attacks from those requiring social engineering, which is independent of the attacker's privilege level.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.