Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is calculating the severity…

A penetration tester is calculating the severity of a vulnerability using the DREAD model. Which of the following factors is assessed under the 'Damage' category?

⚠ Common exam trap

Watch out — candidates often confuse the 'Damage' category with 'Affected Users' (Option D), as both involve impact, but Damage focuses on the severity of harm to data or systems, while Affected Users counts the number of individuals or systems impacted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The potential data loss or system damage that could result from exploitation.

In the DREAD model, the 'Damage' category specifically assesses the potential harm from a successful exploit, such as data loss, system corruption, or service disruption. Option B correctly captures this by focusing on the impact to confidentiality, integrity, or availability, which is the core of the Damage factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The likelihood that an attacker can reproduce the exploit.

    Why it's wrong here

    Reproducibility describes the consistency with which an exploit succeeds when executed against a vulnerable system. While a highly reproducible exploit increases the likelihood of successful compromise, severity scoring in frameworks like CVSS focuses on the direct impact to confidentiality, integrity, and availability, not on how predictably the attack can be repeated. In risk models, reproducibility feeds into the threat/likelihood component, not into the damage/impact component that severity specifically measures.

  • ✓

    The potential data loss or system damage that could result from exploitation.

    Why this is correct

    Severity is fundamentally a measure of the potential adverse consequences of an exploit, such as destruction of data, exposure of sensitive information, or loss of system integrity. Frameworks like CVSS explicitly assess this through impact metrics for confidentiality, integrity, and availability, which directly quantify the degree of harm. Unlike likelihood-oriented factors, damage potential remains a constant property of the vulnerability itself, making it the correct basis for severity calculation.

  • ✗

    How easy it is for an attacker to discover the vulnerability.

    Why it's wrong here

    Discoverability measures how readily an attacker or vulnerability scanner can identify the flaw, often based on factors like exploit availability or system exposure. In standard risk models, this element contributes to the likelihood of exploitation, not to the potential impact that defines severity. A vulnerability can be extremely easy to discover yet cause negligible damage, so discoverability is not a substitute for impact in severity scoring.

  • ✗

    The number of users affected by the vulnerability.

    Why it's wrong here

    The number of users affected is an exposure metric that reflects the breadth of potential victims, not the depth of damage caused by a single exploit. Severity scoring, such as CVSS, examines the inherent impact on the vulnerable system (CIA triad), independent of population size; a vulnerability can have catastrophic severity even if it only impacts a single privileged user. The count of affected users is more appropriately used in risk quantification or prioritization, not in calculating the vulnerability's severity.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.