Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: During a penetration test, the tester identifies…

During a penetration test, the tester identifies a low-risk information disclosure vulnerability in a public-facing web server. The tester includes this finding in the final report. Which component of the risk rating should the tester use to justify the low severity?

⚠ Common exam trap

CompTIA often tests the misconception that exploitability metrics or impact metrics alone determine the severity, when in fact the CVSS base score is the aggregate of both and is the authoritative component for justifying the risk rating in a report.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

CVSS base score

The CVSS base score is the correct component to justify the low severity because it represents the intrinsic and fundamental characteristics of a vulnerability that are constant over time and across user environments. In this case, the information disclosure vulnerability has a low base score due to factors such as low attack complexity and low impact on confidentiality, which are captured in the base metrics. The base score is the standard starting point for communicating severity, making it the appropriate justification for the low-risk rating in the report.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • CVSS base score

    Why this is correct

    The CVSS base score is the standardized, intrinsic measure of vulnerability severity, computed from a weighted combination of exploitability metrics (attack vector, complexity, privileges, user interaction) and impact metrics (confidentiality, integrity, availability) into a single 0–10 score. Because it is derived without temporal or environmental adjustments, it provides a stable, vendor-neutral baseline for prioritization. A low base score directly reflects that the vulnerability's intrinsic severity is minor, which is why the penetration tester classifies it as low risk. Unlike sub-metrics or optional adjusted scores, the base score is the industry-accepted primary reference for severity ratings.

  • Exploitability metrics

    Why it's wrong here

    Exploitability metrics in CVSS quantify the ease of exploitation through factors such as Attack Vector, Attack Complexity, Privileges Required, and User Interaction. They do not account for the consequences of a successful exploit; a vulnerability with trivial exploitability could still have negligible impact, resulting in a low overall score. These metrics are merely inputs to the base score equation and are not designed to represent overall severity. Using them alone would misclassify a finding because they ignore the impact component, which is equally critical to the final score.

  • Impact metrics

    Why it's wrong here

    Impact metrics assess the potential harm to confidentiality, integrity, and availability if a vulnerability is successfully exploited. However, they do not consider the likelihood of exploitation; a severe theoretical impact may be nearly impossible to reach due to high attack complexity or elevated privileges, which would lower the base score. The CVSS base score is a synthesis of both exploitability and impact, so evaluating impact alone would overstate or understate the true severity. Thus, impact metrics cannot justify the low-risk rating because that rating emerges from the combined base score formula.

  • Temporal score

    Why it's wrong here

    The CVSS temporal score adjusts the base score based on time-sensitive factors such as exploit code maturity, remediation level, and report confidence. These factors are not intrinsic properties of the vulnerability; they reflect the current threat landscape (e.g., a public exploit being available) and can change over time. The initial severity assessment for a finding should be grounded in the base score, which is independent of such transient conditions. Relying on the temporal score alone is inappropriate because it assumes a specific stage of the vulnerability lifecycle that does not apply to the tester's static analysis.

About these practice questions

This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.