easyMultiple Choice
PT0-002 Practice Question: A penetration tester is writing a report and…
A penetration tester is writing a report and needs to assign a severity rating to a vulnerability. Which of the following scoring systems is specifically designed to consider Damage, Reproducibility, Exploitability, Affected users, and Discoverability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DREAD
The DREAD model is a risk assessment model that uses these five categories.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
STRIDE
Why it's wrong here
STRIDE is a Microsoft threat modeling framework that categorizes security threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is not a severity scoring system because it does not assign numerical risk ratings or prioritize based on likelihood and impact. Instead, STRIDE is used during design to identify what might go wrong, whereas the question specifically asks for a model with DREAD categories. In a pentest report, severity is typically expressed via CVSS or qualitative scales, not STRIDE.
- ✗
OWASP Risk Rating
Why it's wrong here
The OWASP Risk Rating Methodology evaluates risk using Likelihood and Impact factors, such as threat agent, vulnerability, and technical/business impact, producing a risk level. It does not use the DREAD categories (Damage, Reproducibility, Exploitability, Affected Users, Discoverability) because OWASP's framework decomposes risk into probability and consequence, not into the five DREAD sub-factors. Although OWASP Risk Rating is common for web app findings, it is conceptually distinct from DREAD and cannot be the correct answer when DREAD categories are explicitly named.
- ✗
CVSS
Why it's wrong here
CVSS (Common Vulnerability Scoring System) is the industry-standard severity scoring system that uses base, temporal, and environmental metric groups, each with sub-metrics like Attack Vector, User Interaction, and Exploit Code Maturity. It produces a numeric 0-10 score derived from a mathematical formula, but it does not include the DREAD categories. DREAD, in contrast, is qualitative and rates Damage, Reproducibility, Exploitability, Affected users, and Discoverability individually, then averages them. Therefore, CVSS is designed for standardized vulnerability scoring, not for a model based on DREAD's five dimensions.
- ✓
DREAD
Why this is correct
DREAD is a risk-scoring model that ranks threats by scoring each of five categories: Damage (potential loss), Reproducibility (ease of recreating the attack), Exploitability (effort required to exploit), Affected users (number of users impacted), and Discoverability (likelihood the vulnerability is found). Each category is scored on a consistent scale (e.g., 1-10) and the scores are averaged to produce an overall risk rating. Because the question explicitly asks for the model with DREAD categories, DREAD is the correct answer.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.