hardMultiple Choice
PT0-002 Practice Question: A penetration tester is evaluating…
A penetration tester is evaluating vulnerabilities using the DREAD model. For a specific vulnerability, the tester assigns the following scores: Damage=8, Reproducibility=7, Exploitability=9, Affected users=6, Discoverability=5. Which of the following is the overall DREAD risk rating?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
7
DREAD scores are averaged across the five categories. Compute (8+7+9+6+5)/5 = 35/5 = 7.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
9
Why it's wrong here
9 is a critical CVSS score (9.0-10.0), but it is not the arithmetic mean of the vulnerability scores. Selecting 9 often comes from anchoring on the highest-severity finding in the report, which is a common heuristic but loses information about lower-severity items. The correct average, computed as the sum of all base scores divided by the total number of findings, is 7, so 9 overstates the overall risk.
- ✗
8
Why it's wrong here
8 may be a base score attached to one of the individual vulnerabilities, yet it is not the mean. A frequent mistake is to report the mode or the most frequent score class; if the dataset is small, 8 could be misidentified as the central value. When all scores are summed and divided correctly, the result is 7, meaning 8 is an overestimate of the central tendency and conflates a single high-severity finding with the overall average.
- ✓
7
Why this is correct
The average vulnerability score equals 7 because the sum of all CVSS base scores divided by the number of assessed findings yields exactly 7. In CVSS v3.1, 7.0 falls in the High severity band (7.0-8.9), accurately reflecting a set that contains both critical and medium findings. This is the correct mean, and it is the appropriate metric for communicating baseline risk posture across the discovered vulnerabilities.
- ✗
6
Why it's wrong here
6 is a Medium severity CVSS score (4.0-6.9) and likely represents the lowest-severity finding in the assessed group. Choosing 6 may result from using the minimum score rather than the mean or from applying a nonstandard weighting that down-weights high-impact vulnerabilities. The arithmetic mean of the reported CVSS scores is 7, so 6 underestimates community risk and misrepresents the severity distribution.
Go deeper
Related to this question
Learn chapter
PowerShell for Penetration Testing
Key term
Risk rating
A risk rating is a score or label assigned to a potential security threat or vulnerability that indicates how likely it is to cause harm and how severe that harm would be.
Key term
Exploitability
Exploitability is a measure of how easy or difficult it is for an attacker to take advantage of a vulnerability in a system or software.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.