Courseiva
easyMultiple Select

PT0-002 Practice Question: Which TWO of the following are components of the…

Which TWO of the following are components of the DREAD model for risk assessment? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reproducibility

DREAD stands for Damage, Reproducibility, Exploitability, Affected users, Discoverability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Likelihood

    Why it's wrong here

    Likelihood is not a letter in the DREAD acronym; DREAD stands for Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. Although likelihood is a core concept in risk assessment frameworks such as CVSS or FAIR, DREAD deliberately omits it as a separate item because likelihood is instead approximated by combining Reproducibility and Exploitability. Including Likelihood would duplicate those factors and distort the final risk score.

  • ✗

    Severity

    Why it's wrong here

    Severity is the output of a DREAD assessment, not one of its constituent categories. The five DREAD factors are scored individually on a 0-to-10 scale, and those scores are averaged to assign an overall severity rating; severity therefore represents the calculated result, not an input. Confusing Severity with a component reverses the relationship and undermines the model's scoring methodology.

  • ✓

    Reproducibility

    Why this is correct

    Reproducibility is a genuine DREAD component that measures how consistently an exploit attempt yields the same successful result. An attack that works every time it is attempted receives a high score, whereas one that succeeds only occasionally gets a low score; this directly affects the reliability of the threat event. In the scoring formula, Reproducibility is weighted equally with the other four factors when calculating the overall risk value.

  • ✗

    Impact

    Why it's wrong here

    Impact is not one of the five DREAD categories; the model instead uses Affected users (how many users are touched) and Damage potential (how severe the harm is) as separate measures. In other frameworks like STRIDE or CVSS, Impact is a broad catch-all term for confidentiality, integrity, and availability loss, which conflates the scope and magnitude of harm. By splitting impact into distinct DREAD components, the model avoids that ambiguity but does not include an 'Impact' field itself.

  • ✓

    Damage

    Why this is correct

    Damage potential is a DREAD component that quantifies the maximum harm a successful exploit could cause, such as unauthorized data disclosure, service interruption, or complete system takeover. It is scored from 0 (no damage) to 10 (total compromise with administrative privileges), and it feeds directly into the averaged risk calculation. Although the name sounds like 'Impact,' Damage potential is the model's specific term for the technical severity of the outcome, not a generic business-impact label.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.