PenTest+ V2 Risk Rating and Severity Scoring in Reports Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 13, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. In a penetration test report, how should you communicate severity ratings to non-technical stakeholders?

Submit
Please wait...
About This Quiz
PenTest+ V2 Risk Rating and Severity Scoring In Reports Quiz - Quiz

This quiz assesses your understanding of risk rating methodologies, severity scoring frameworks, and vulnerability classification in penetration testing reports. Learn how to evaluate and communicate security findings using industry-standard rating systems like CVSS, and how to prioritize remediation efforts based on risk levels. Essential for security professionals who need to... see moreproduce clear, actionable penetration test documentation. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. What is the primary goal of risk rating in penetration test reporting?

Submit

3. In CVSS, an Availability Impact of 'None' indicates the vulnerability does NOT affect ____ of systems or services.

Submit

4. Which communication principle is most important when presenting severity ratings to executive leadership?

Submit

5. A vulnerability with Integrity Impact of 'High' means the vulnerability allows ____ of information.

Submit

6. In risk reporting, what does 'compensating controls' refer to in the context of severity adjustment?

Submit

7. Which CVSS impact metric specifically measures unauthorized access to information?

Submit

8. A vulnerability requiring valid user credentials to exploit would have Privileges Required set to ____ in CVSS.

Submit

9. What is the primary advantage of using standardized risk rating systems like CVSS in reports?

Submit

10. Which of the following is an example of a Critical severity vulnerability?

Submit

11. What does CVSS stand for in the context of vulnerability severity scoring?

Submit

12. Which CVSS metric measures whether the vulnerability impact is contained to the vulnerable component or spreads to other systems?

Submit

13. A vulnerability affecting an unauthenticated remote attacker with low complexity would have an Attack Vector of ____ in CVSS.

Submit

14. Which of the following best describes the purpose of severity scoring in penetration test reports?

Submit

15. In risk assessment, which formula is commonly used: Risk = ____ × Vulnerability × Impact?

Submit

16. What does the Temporal metric group in CVSS account for?

Submit

17. Which factor is NOT part of the CVSS v3.1 base metric group?

Submit

18. A vulnerability with a CVSS base score of 8.5 would typically be rated as ____ severity.

Submit

19. In CVSS v3.1, what is the score range for a High severity rating?

Submit

20. Which CVSS metric describes whether a vulnerability requires user interaction to be exploited?

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
In a penetration test report, how should you communicate severity...
What is the primary goal of risk rating in penetration test reporting?
In CVSS, an Availability Impact of 'None' indicates the vulnerability...
Which communication principle is most important when presenting...
A vulnerability with Integrity Impact of 'High' means the...
In risk reporting, what does 'compensating controls' refer to in the...
Which CVSS impact metric specifically measures unauthorized access to...
A vulnerability requiring valid user credentials to exploit would have...
What is the primary advantage of using standardized risk rating...
Which of the following is an example of a Critical severity...
What does CVSS stand for in the context of vulnerability severity...
Which CVSS metric measures whether the vulnerability impact is...
A vulnerability affecting an unauthenticated remote attacker with low...
Which of the following best describes the purpose of severity scoring...
In risk assessment, which formula is commonly used: Risk = ____ ×...
What does the Temporal metric group in CVSS account for?
Which factor is NOT part of the CVSS v3.1 base metric group?
A vulnerability with a CVSS base score of 8.5 would typically be rated...
In CVSS v3.1, what is the score range for a High severity rating?
Which CVSS metric describes whether a vulnerability requires user...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!