
CompTIACySA+
Domain 2Objective 2
Assessment Tool Output CS0-003 Practice Questions (Page 6)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
30%of the exam
Questions 26–28
- 26
A vulnerability scanner reports a 'High' severity vulnerability on a web server. The server is running a legacy application that cannot be patched without a full outage, which would impact business operations. The server is also accessible from the internet. What is the most appropriate risk treatment option?
Select an answer first - 27
A vulnerability scanner output includes a finding with the status 'Exploitable' and a CVSS score of 7.5. What does the 'Exploitable' status indicate?
Select an answer first - 28
A web application scanner output includes a finding with the CWE identifier CWE-89. Which vulnerability class does this represent?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CS0-003
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.