easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: During a penetration test, the tester identifies…
During a penetration test, the tester identifies a low-risk information disclosure vulnerability in a public-facing web server. The tester includes this finding in the final report. Which component of the risk rating should the tester use to justify the low severity?
⚠ Common exam trap
CompTIA often tests the misconception that exploitability metrics or impact metrics alone determine the severity, when in fact the CVSS base score is the aggregate of both and is the authoritative component for justifying the risk rating in a report.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CVSS base score
The CVSS base score is the correct component to justify the low severity because it represents the intrinsic and fundamental characteristics of a vulnerability that are constant over time and across user environments. In this case, the information disclosure vulnerability has a low base score due to factors such as low attack complexity and low impact on confidentiality, which are captured in the base metrics. The base score is the standard starting point for communicating severity, making it the appropriate justification for the low-risk rating in the report.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CVSS base score
Why this is correct
The CVSS base score is the standardized, intrinsic measure of vulnerability severity, computed from a weighted combination of exploitability metrics (attack vector, complexity, privileges, user interaction) and impact metrics (confidentiality, integrity, availability) into a single 0–10 score. Because it is derived without temporal or environmental adjustments, it provides a stable, vendor-neutral baseline for prioritization. A low base score directly reflects that the vulnerability's intrinsic severity is minor, which is why the penetration tester classifies it as low risk. Unlike sub-metrics or optional adjusted scores, the base score is the industry-accepted primary reference for severity ratings.
- ✗
Exploitability metrics
Why it's wrong here
Exploitability metrics in CVSS quantify the ease of exploitation through factors such as Attack Vector, Attack Complexity, Privileges Required, and User Interaction. They do not account for the consequences of a successful exploit; a vulnerability with trivial exploitability could still have negligible impact, resulting in a low overall score. These metrics are merely inputs to the base score equation and are not designed to represent overall severity. Using them alone would misclassify a finding because they ignore the impact component, which is equally critical to the final score.
- ✗
Impact metrics
Why it's wrong here
Impact metrics assess the potential harm to confidentiality, integrity, and availability if a vulnerability is successfully exploited. However, they do not consider the likelihood of exploitation; a severe theoretical impact may be nearly impossible to reach due to high attack complexity or elevated privileges, which would lower the base score. The CVSS base score is a synthesis of both exploitability and impact, so evaluating impact alone would overstate or understate the true severity. Thus, impact metrics cannot justify the low-risk rating because that rating emerges from the combined base score formula.
- ✗
Temporal score
Why it's wrong here
The CVSS temporal score adjusts the base score based on time-sensitive factors such as exploit code maturity, remediation level, and report confidence. These factors are not intrinsic properties of the vulnerability; they reflect the current threat landscape (e.g., a public exploit being available) and can change over time. The initial severity assessment for a finding should be grounded in the base score, which is independent of such transient conditions. Relying on the temporal score alone is inappropriate because it assumes a specific stage of the vulnerability lifecycle that does not apply to the tester's static analysis.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Risk rating
A risk rating is a score or label assigned to a potential security threat or vulnerability that indicates how likely it is to cause harm and how severe that harm would be.
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.