nerdexam
CompTIA

PT0-003 · Question #77

A penetration tester needs to evaluate the order in which the next systems will be selected for testing. Given the following output: Which of the following targets should the tester select next?

The correct answer is A. fileserver. Evaluation Criteria: CVSS (Common Vulnerability Scoring System): Indicates the severity of vulnerabilities, with higher scores representing more critical vulnerabilities. EPSS (Exploit Prediction Scoring System): Estimates the likelihood of a vulnerability being exploited in the

Submitted by neha2k· Mar 6, 2026Vulnerability Discovery and Analysis

Question

A penetration tester needs to evaluate the order in which the next systems will be selected for testing. Given the following output:

Which of the following targets should the tester select next?

Exhibit

PT0-003 question #77 exhibit

Options

  • Afileserver
  • Bhrdatabase
  • Clegaldatabase
  • Dfinancesite

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    4% (1)
  • C
    4% (1)
  • D
    14% (4)

Explanation

Evaluation Criteria: CVSS (Common Vulnerability Scoring System): Indicates the severity of vulnerabilities, with higher scores representing more critical vulnerabilities. EPSS (Exploit Prediction Scoring System): Estimates the likelihood of a vulnerability being exploited in the wild. hrdatabase: CVSS = 9.9, EPSS = 0.50 financesite: CVSS = 8.0, EPSS = 0.01 legaldatabase: CVSS = 8.2, EPSS = 0.60 fileserver: CVSS = 7.6, EPSS = 0.90 Selection Justification: fileserver has the highest EPSS score of 0.90, indicating a high likelihood of exploitation despite having a slightly lower CVSS score compared to other targets. This makes it a critical target for immediate testing to mitigate potential exploitation risks.

Topics

#target prioritization#network analysis#vulnerability assessment

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice