hardMultiple Choice
PT0-002 Practice Question: A penetration tester is writing a report that…
A penetration tester is writing a report that includes a vulnerability with a CVSS score of 9.8. The client's security team argues that the score should be lower due to compensating controls. How should the tester respond in the report?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the base CVSS score and include a note about the compensating controls
The correct response is A: report the base CVSS score and include a note about the compensating controls. CVSS base scores are intrinsic to the vulnerability itself and do not account for environmental or compensating controls, so the 9.8 base score should remain unchanged in the report. Compensating controls are instead reflected through the CVSS temporal and environmental metric groups (e.g., Environmental score via modified impact and exploitability metrics), which can be documented separately. Option B is wrong because the tester should not simply defer the scoring decision to the client, and CVSS scores are not adjusted by client preference. Option C is incorrect because omitting the CVSS score removes valuable, standardized severity information. Option D is incorrect because arbitrarily lowering the base score misrepresents the vulnerability and violates CVSS methodology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Report the base CVSS score and include a note about the compensating controls
Why this is correct
CVSS base scores assume no environmental mitigations, so the tester must report 9.8 unchanged and add a note describing the compensating controls. Recalculating or lowering the base score would misrepresent the vulnerability; the note preserves accuracy while acknowledging the client's controls.
- ✗
Report both scores and let the client decide
Why it's wrong here
Reporting both scores defers the analytical judgement the tester was engaged to provide; CVSS v4.0 already incorporates mitigations through its Threat and Environmental metric groups, so a separate client-adjusted figure duplicates that mechanism. Presenting two scores without reconciliation is what a collaborative workshop suits, not a formal deliverable.
- ✗
Remove the CVSS score entirely to avoid disagreement
Why it's wrong here
Deleting the score removes the standardised severity metric the client needs for prioritisation and compliance, and conceals rather than resolves the disagreement. Omitting scores suits contexts where no CVSS vector was calculated; here the tester should retain the base score and document the compensating controls separately.
- ✗
Adjust the CVSS score lower to reflect the client's compensating controls
Why it's wrong here
CVSS base score should remain objective.
Go deeper
Related to this question
Learn chapter
Physical Security Testing Techniques
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
Key term
Exploitability
Exploitability is a measure of how easy or difficult it is for an attacker to take advantage of a vulnerability in a system or software.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.