easyMultiple Select
PT0-002 Practice Question: Which TWO of the following are components of the…
Which TWO of the following are components of the DREAD model for risk assessment? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reproducibility
DREAD stands for Damage, Reproducibility, Exploitability, Affected users, Discoverability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Likelihood
Why it's wrong here
Likelihood is not a letter in the DREAD acronym; DREAD stands for Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. Although likelihood is a core concept in risk assessment frameworks such as CVSS or FAIR, DREAD deliberately omits it as a separate item because likelihood is instead approximated by combining Reproducibility and Exploitability. Including Likelihood would duplicate those factors and distort the final risk score.
- ✗
Severity
Why it's wrong here
Severity is the output of a DREAD assessment, not one of its constituent categories. The five DREAD factors are scored individually on a 0-to-10 scale, and those scores are averaged to assign an overall severity rating; severity therefore represents the calculated result, not an input. Confusing Severity with a component reverses the relationship and undermines the model's scoring methodology.
- ✓
Reproducibility
Why this is correct
Reproducibility is a genuine DREAD component that measures how consistently an exploit attempt yields the same successful result. An attack that works every time it is attempted receives a high score, whereas one that succeeds only occasionally gets a low score; this directly affects the reliability of the threat event. In the scoring formula, Reproducibility is weighted equally with the other four factors when calculating the overall risk value.
- ✗
Impact
Why it's wrong here
Impact is not one of the five DREAD categories; the model instead uses Affected users (how many users are touched) and Damage potential (how severe the harm is) as separate measures. In other frameworks like STRIDE or CVSS, Impact is a broad catch-all term for confidentiality, integrity, and availability loss, which conflates the scope and magnitude of harm. By splitting impact into distinct DREAD components, the model avoids that ambiguity but does not include an 'Impact' field itself.
- ✓
Damage
Why this is correct
Damage potential is a DREAD component that quantifies the maximum harm a successful exploit could cause, such as unauthorized data disclosure, service interruption, or complete system takeover. It is scored from 0 (no damage) to 10 (total compromise with administrative privileges), and it feeds directly into the averaged risk calculation. Although the name sounds like 'Impact,' Damage potential is the model's specific term for the technical severity of the outcome, not a generic business-impact label.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.