Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is writing a report that…

A penetration tester is writing a report that includes a vulnerability with a CVSS score of 9.8. The client's security team argues that the score should be lower due to compensating controls. How should the tester respond in the report?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the base CVSS score and include a note about the compensating controls

The correct response is A: report the base CVSS score and include a note about the compensating controls. CVSS base scores are intrinsic to the vulnerability itself and do not account for environmental or compensating controls, so the 9.8 base score should remain unchanged in the report. Compensating controls are instead reflected through the CVSS temporal and environmental metric groups (e.g., Environmental score via modified impact and exploitability metrics), which can be documented separately. Option B is wrong because the tester should not simply defer the scoring decision to the client, and CVSS scores are not adjusted by client preference. Option C is incorrect because omitting the CVSS score removes valuable, standardized severity information. Option D is incorrect because arbitrarily lowering the base score misrepresents the vulnerability and violates CVSS methodology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Report the base CVSS score and include a note about the compensating controls

    Why this is correct

    CVSS base scores assume no environmental mitigations, so the tester must report 9.8 unchanged and add a note describing the compensating controls. Recalculating or lowering the base score would misrepresent the vulnerability; the note preserves accuracy while acknowledging the client's controls.

  • ✗

    Report both scores and let the client decide

    Why it's wrong here

    Reporting both scores defers the analytical judgement the tester was engaged to provide; CVSS v4.0 already incorporates mitigations through its Threat and Environmental metric groups, so a separate client-adjusted figure duplicates that mechanism. Presenting two scores without reconciliation is what a collaborative workshop suits, not a formal deliverable.

  • ✗

    Remove the CVSS score entirely to avoid disagreement

    Why it's wrong here

    Deleting the score removes the standardised severity metric the client needs for prioritisation and compliance, and conceals rather than resolves the disagreement. Omitting scores suits contexts where no CVSS vector was calculated; here the tester should retain the base score and document the compensating controls separately.

  • ✗

    Adjust the CVSS score lower to reflect the client's compensating controls

    Why it's wrong here

    CVSS base score should remain objective.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.