Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester uses a custom severity…

A penetration tester uses a custom severity rating based on business context. The tester determines the likelihood of exploitation is high and the business impact is low. According to a standard risk matrix, what should the overall severity be?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Medium

In many risk matrices, high likelihood combined with low impact typically results in a medium severity rating.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Medium

    Why this is correct

    In a custom risk-based severity matrix, severity is derived from the intersection of likelihood and impact. When likelihood is high but impact is low, the resulting severity is typically medium because the high probability of occurrence is tempered by the limited damage or business impact of the vulnerability. This reflects a balanced scoring approach where neither factor dominates the final rating, placing it above low but below high on the ordinal severity scale.

  • ✗

    High

    Why it's wrong here

    High severity cannot be justified with low impact alone. A High rating in a standard risk matrix requires at least medium impact paired with high likelihood, or high impact with at least medium likelihood. Since the scenario specifies low impact, the severity is capped below the High threshold despite the high likelihood, avoiding over-prioritization of frequent but inconsequential security issues.

  • ✗

    Low

    Why it's wrong here

    Low severity requires both low likelihood and low impact, or in some matrices, low likelihood is the dominant factor even when impact is medium. In this case, likelihood is explicitly high, which immediately disqualifies the finding from a Low rating. High probability of occurrence elevates the risk above the minimal concern implied by Low, so the custom matrix must not output Low even though impact is low.

  • ✗

    Critical

    Why it's wrong here

    Critical severity customarily demands high impact, often combined with high or very high likelihood, because it represents a catastrophic or security-compromising event. Low impact fundamentally conflicts with this classification, regardless of how likely the event is, since critical findings are defined by severe consequences such as major financial loss, data breach, or full system compromise. Therefore, high likelihood alone cannot raise the rating to the most severe tier.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.