hardMultiple Choice
PT0-002 Practice Question: A penetration tester uses a custom severity…
A penetration tester uses a custom severity rating based on business context. The tester determines the likelihood of exploitation is high and the business impact is low. According to a standard risk matrix, what should the overall severity be?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Medium
In many risk matrices, high likelihood combined with low impact typically results in a medium severity rating.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Medium
Why this is correct
In a custom risk-based severity matrix, severity is derived from the intersection of likelihood and impact. When likelihood is high but impact is low, the resulting severity is typically medium because the high probability of occurrence is tempered by the limited damage or business impact of the vulnerability. This reflects a balanced scoring approach where neither factor dominates the final rating, placing it above low but below high on the ordinal severity scale.
- ✗
High
Why it's wrong here
High severity cannot be justified with low impact alone. A High rating in a standard risk matrix requires at least medium impact paired with high likelihood, or high impact with at least medium likelihood. Since the scenario specifies low impact, the severity is capped below the High threshold despite the high likelihood, avoiding over-prioritization of frequent but inconsequential security issues.
- ✗
Low
Why it's wrong here
Low severity requires both low likelihood and low impact, or in some matrices, low likelihood is the dominant factor even when impact is medium. In this case, likelihood is explicitly high, which immediately disqualifies the finding from a Low rating. High probability of occurrence elevates the risk above the minimal concern implied by Low, so the custom matrix must not output Low even though impact is low.
- ✗
Critical
Why it's wrong here
Critical severity customarily demands high impact, often combined with high or very high likelihood, because it represents a catastrophic or security-compromising event. Low impact fundamentally conflicts with this classification, regardless of how likely the event is, since critical findings are defined by severe consequences such as major financial loss, data breach, or full system compromise. Therefore, high likelihood alone cannot raise the rating to the most severe tier.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.