nerdexam
CompTIA

PT0-003 · Question #302

After completing vulnerability scans for a given test, a penetration tester needs to prioritize which potential assets are in scope and should be exploited first. Given the following scanner output…

The correct answer is C. 3. The public website is internet-facing and the validation indicates sensitive token values were actually observed in responses, making the issue both highly exposed and credibly confirmed. This combination of likelihood and impact typically represents the highest immediate…

Submitted by olafpl· Mar 6, 2026Vulnerability discovery and analysis

Question

After completing vulnerability scans for a given test, a penetration tester needs to prioritize which potential assets are in scope and should be exploited first. Given the following scanner output:

Which of the following findings should the tester prioritize first based upon a consideration of risk to the organization?

Exhibit

PT0-003 question #302 exhibit

Options

  • A1
  • B2
  • C3
  • D4

How the community answered

(59 responses)
  • A
    5% (3)
  • B
    8% (5)
  • C
    64% (38)
  • D
    22% (13)

Explanation

The public website is internet-facing and the validation indicates sensitive token values were actually observed in responses, making the issue both highly exposed and credibly confirmed. This combination of likelihood and impact typically represents the highest immediate organizational risk and should be prioritized for exploitation/verification first.

Topics

#risk assessment#vulnerability prioritization#vulnerability management#reporting

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice