mediumMultiple Choice
PT0-002 Practice Question: A penetration tester has completed the test and…
A penetration tester has completed the test and is preparing the final report. The client requested a risk rating for each vulnerability. Which of the following frameworks is MOST commonly used to standardize vulnerability severity ratings in penetration testing reports?
⚠ Common exam trap
It's easy for candidates to confuse OWASP Top 10 (a risk categorization list) with a scoring framework, or mistake CVE (an identifier system) for a severity rating system, when CVSS is the only option that provides a standardized numerical severity scale for individual vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CVSS
CVSS (Common Vulnerability Scoring System) is the industry-standard framework for assigning numeric severity scores (0-10) to vulnerabilities based on metrics like attack vector, complexity, and impact. Penetration testers use CVSS scores to provide consistent, quantitative risk ratings that clients can compare across findings. OWASP Top 10 is a list of web application risk categories, not a scoring system, and CVE is a vulnerability identifier database, not a rating framework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OWASP Top 10
Why it's wrong here
OWASP Top 10 is a widely referenced awareness document that catalogs the most common and critical web application security risk categories (e.g., injection, broken access control), not an individual vulnerability scoring system. It groups broad vulnerability classes based on prevalence and impact but does not assign a specific severity score to a given finding. In a pentest report, using OWASP Top 10 alone would lack the per-vulnerability granularity needed to triage and prioritize issues.
- ✓
CVSS
Why this is correct
The Common Vulnerability Scoring System (CVSS) is the correct choice because it provides a standardized, repeatable methodology for assigning severity scores to individual vulnerabilities. CVSS uses metric groups (base, temporal, and environmental) with vectors such as attack vector, attack complexity, privileges required, user interaction, and impact to produce a numerical score from 0.0 to 10.0. This allows pentesters to communicate vulnerability severity consistently and objectively, enabling stakeholders to prioritize remediation efforts across different systems and findings.
- ✗
CVE
Why it's wrong here
CVE (Common Vulnerabilities and Exposures) is a dictionary of publicly disclosed vulnerabilities, each assigned a unique identifier (e.g., CVE-2024-1234), but it does not provide any risk or severity rating. While CVE entries often reference a CVSS score, the CVE itself is simply an identifier for a known issue. Therefore, citing a CVE ID in a pentest report identifies the vulnerability but does not convey its severity, making it an insufficient scoring framework.
- ✗
NIST SP 800-115
Why it's wrong here
NIST SP 800-115 is a technical guide that outlines methodologies, steps, and best practices for conducting security assessments and penetration tests. It covers planning, discovery, attack, and reporting phases, but it is not a vulnerability scoring framework. It provides recommendations on how to test, not how to rate the severity of discovered vulnerabilities, so it cannot be used as a scoring system in a pentest report.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
CVE
CVE stands for Common Vulnerabilities and Exposures, which is a publicly available list of standardized identifiers for known security vulnerabilities in software and hardware.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.