easyMultiple Choice
PT0-002 Practice Question: Is an example of a custom severity rating based…
Which of the following is an example of a custom severity rating based on business context?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk rating of 'Critical' based on high business impact and likelihood
Custom severity often uses impact and likelihood to determine risk, as not all vulnerabilities affect the business equally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DREAD score of 7
Why it's wrong here
DREAD is a standardized threat-modeling methodology that rates each threat via five categories (Damage, Reproducibility, Exploitability, Affected users, Discoverability) to produce a numeric score. A score of 7 is merely the product of that public, predefined model rather than an organizationally tailored severity scale. Because the rating derives entirely from DREAD's generic formula, it does not incorporate business-specific impact or context, so it is not a custom severity rating.
- ✗
High/Medium/Low based on CVSS
Why it's wrong here
CVSS already provides an official qualitative severity band (Low, Medium, High, or Critical) derived from its numeric base score. Classifying a finding as 'High' or 'Medium' based on that CVSS mapping is simply applying the standard's own threshold, not creating a bespoke rating. The decision lacks any input from business impact, asset criticality, or likelihood, so it remains a default CVSS label rather than a custom severity scale.
- ✗
CVSS score of 9.0
Why it's wrong here
A CVSS score of 9.0 is a specific numerical output from the standardized CVSS calculator, which evaluates only intrinsic technical characteristics of the vulnerability. This score is deterministic and vendor-neutral, independent of how the vulnerability affects a particular organization's environment or operations. Since no business context or custom weighting is involved, it cannot qualify as an example of a custom severity rating.
- ✓
Risk rating of 'Critical' based on high business impact and likelihood
Why this is correct
A risk rating of 'Critical' that is explicitly predicated on high business impact and high likelihood is a bespoke severity assessment, because those factors are derived from the organization's own risk context and priorities. Unlike standard CVSS or DREAD scores, this rating maps technical severity to business consequences, which is exactly what a custom severity rating is intended to do. It reflects an informed risk decision, not merely a formulaic score.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.