
CompTIACySA+
Domain 2Objective 3
Vulnerability Prioritization CS0-003 Practice Questions (Page 4)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
30%of the exam
Questions 16–20
- 16
A vulnerability scan flags a critical SQL injection vulnerability in a custom web application. The security analyst reviews the finding and discovers the scanner detected the issue by sending a benign test payload that returned an error message containing database syntax. The application's development team states the input is properly parameterized. What should the analyst do NEXT?
Select an answer first - 17
A vulnerability scanner reports a vulnerability with a CVSS vector string: AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N. The vulnerability is found on a developer workstation. The analyst is reviewing the finding. What is the MOST accurate interpretation?
Select an answer first - 18
A zero-day vulnerability is announced in a widely used web server software. The organization uses this software for its public-facing website. The vendor has released a patch, but the organization's change management process requires a 30-day testing period before production deployment. The vulnerability is being actively exploited. What is the BEST course of action?
Select an answer first - 19
A security team has limited resources and must prioritize among three vulnerabilities: (1) a critical CVSS 9.8 vulnerability in an internet-facing web server with a known exploit, (2) a high CVSS 8.1 vulnerability in an internal database that stores customer PII with no known exploit, and (3) a medium CVSS 6.5 vulnerability in a domain controller with a known exploit. The organization is subject to strict data protection regulations. Which vulnerability should be prioritized FIRST?
Select an answer first - 20
A security team discovers a vulnerability in a custom application that requires the attacker to be authenticated as a low-privileged user and to win a race condition. The application is used by only 50 internal employees. The team has limited remediation resources and must decide whether to patch now or defer. What is the MOST important factor in this decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.