Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is evaluating…

A penetration tester is evaluating vulnerabilities using the DREAD model. For a specific vulnerability, the tester assigns the following scores: Damage=8, Reproducibility=7, Exploitability=9, Affected users=6, Discoverability=5. Which of the following is the overall DREAD risk rating?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

7

DREAD scores are averaged across the five categories. Compute (8+7+9+6+5)/5 = 35/5 = 7.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    9

    Why it's wrong here

    9 is a critical CVSS score (9.0-10.0), but it is not the arithmetic mean of the vulnerability scores. Selecting 9 often comes from anchoring on the highest-severity finding in the report, which is a common heuristic but loses information about lower-severity items. The correct average, computed as the sum of all base scores divided by the total number of findings, is 7, so 9 overstates the overall risk.

  • ✗

    8

    Why it's wrong here

    8 may be a base score attached to one of the individual vulnerabilities, yet it is not the mean. A frequent mistake is to report the mode or the most frequent score class; if the dataset is small, 8 could be misidentified as the central value. When all scores are summed and divided correctly, the result is 7, meaning 8 is an overestimate of the central tendency and conflates a single high-severity finding with the overall average.

  • ✓

    7

    Why this is correct

    The average vulnerability score equals 7 because the sum of all CVSS base scores divided by the number of assessed findings yields exactly 7. In CVSS v3.1, 7.0 falls in the High severity band (7.0-8.9), accurately reflecting a set that contains both critical and medium findings. This is the correct mean, and it is the appropriate metric for communicating baseline risk posture across the discovered vulnerabilities.

  • ✗

    6

    Why it's wrong here

    6 is a Medium severity CVSS score (4.0-6.9) and likely represents the lowest-severity finding in the assessed group. Choosing 6 may result from using the minimum score rather than the mean or from applying a nonstandard weighting that down-weights high-impact vulnerabilities. The arithmetic mean of the reported CVSS scores is 7, so 6 underestimates community risk and misrepresents the severity distribution.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.