hardMultiple Choice
PT0-002 Practice Question: A penetration tester uses the CVSS base score to…
A penetration tester uses the CVSS base score to rate a vulnerability. The tester finds that the vulnerability has a high CVSS score but the affected system is isolated from the internet and has no sensitive data. Which approach should the tester take when assigning an overall severity rating?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adjust the severity lower to reflect the reduced business impact.
CVSS is a good starting point but should be adjusted based on business context such as impact and likelihood in the specific environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the severity because the system is isolated and may be overlooked.
Why it's wrong here
Increasing the severity because isolation may cause the system to be overlooked confuses vulnerability severity with risk-management process. In CVSS, isolation actually reduces the attack surface and reduces the potential impact, which would lower the environmental score (e.g., modified attack vector), not raise it. The possibility that the system is forgotten is an operational mistake, not a technical factor that makes the flaw more severe.
- ✓
Adjust the severity lower to reflect the reduced business impact.
Why this is correct
Adjusting the severity downward is correct because CVSS's base score captures the intrinsic characteristics of the vulnerability in a generic context, not the actual business context. Using the environmental score, the tester would modify impact metrics to reflect an isolated system and low data sensitivity, lowering the overall rating. This alignment of severity to business impact is exactly how a penetration test adds value beyond a raw scanner CVSS number.
- ✗
Remove the finding from the report since the system is isolated.
Why it's wrong here
Removing the finding is incorrect because every vulnerability that could be exploited should be reported to give the organization complete insight; even on an isolated system, an attacker who compromises via a different vector could use it as a pivot point. The appropriate action is to report the vulnerability with a reduced, context-aware severity rating, not to delete it. Pentest reports should be comprehensive, and hiding flaws on isolated systems can lead to unpatched weaknesses later being exposed when the network changes.
- ✗
Use the CVSS score as the final severity rating.
Why it's wrong here
Treating the base score as the final rating ignores the other two CVSS component groups: temporal and environmental metrics. The base score is meant to be a standardized, context-independent measure of how serious a flaw is under generic conditions, whereas the organization-specific environment (such as network isolation and data sensitivity) must be factored in for the final severity. Failing to do so typically overstates risk and can misprioritize remediation, especially when the system hosts no sensitive data and is not reachable from the internet.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.