Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester has completed the test and…

A penetration tester has completed the test and is preparing the final report. The client requested a risk rating for each vulnerability. Which of the following frameworks is MOST commonly used to standardize vulnerability severity ratings in penetration testing reports?

⚠ Common exam trap

It's easy for candidates to confuse OWASP Top 10 (a risk categorization list) with a scoring framework, or mistake CVE (an identifier system) for a severity rating system, when CVSS is the only option that provides a standardized numerical severity scale for individual vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CVSS

CVSS (Common Vulnerability Scoring System) is the industry-standard framework for assigning numeric severity scores (0-10) to vulnerabilities based on metrics like attack vector, complexity, and impact. Penetration testers use CVSS scores to provide consistent, quantitative risk ratings that clients can compare across findings. OWASP Top 10 is a list of web application risk categories, not a scoring system, and CVE is a vulnerability identifier database, not a rating framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    OWASP Top 10

    Why it's wrong here

    OWASP Top 10 is a widely referenced awareness document that catalogs the most common and critical web application security risk categories (e.g., injection, broken access control), not an individual vulnerability scoring system. It groups broad vulnerability classes based on prevalence and impact but does not assign a specific severity score to a given finding. In a pentest report, using OWASP Top 10 alone would lack the per-vulnerability granularity needed to triage and prioritize issues.

  • ✓

    CVSS

    Why this is correct

    The Common Vulnerability Scoring System (CVSS) is the correct choice because it provides a standardized, repeatable methodology for assigning severity scores to individual vulnerabilities. CVSS uses metric groups (base, temporal, and environmental) with vectors such as attack vector, attack complexity, privileges required, user interaction, and impact to produce a numerical score from 0.0 to 10.0. This allows pentesters to communicate vulnerability severity consistently and objectively, enabling stakeholders to prioritize remediation efforts across different systems and findings.

  • ✗

    CVE

    Why it's wrong here

    CVE (Common Vulnerabilities and Exposures) is a dictionary of publicly disclosed vulnerabilities, each assigned a unique identifier (e.g., CVE-2024-1234), but it does not provide any risk or severity rating. While CVE entries often reference a CVSS score, the CVE itself is simply an identifier for a known issue. Therefore, citing a CVE ID in a pentest report identifies the vulnerability but does not convey its severity, making it an insufficient scoring framework.

  • ✗

    NIST SP 800-115

    Why it's wrong here

    NIST SP 800-115 is a technical guide that outlines methodologies, steps, and best practices for conducting security assessments and penetration tests. It covers planning, discovery, attack, and reporting phases, but it is not a vulnerability scoring framework. It provides recommendations on how to test, not how to rate the severity of discovered vulnerabilities, so it cannot be used as a scoring system in a pentest report.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.