ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 313 - CAS-004 discussion

Report
Export

A security analyst is using data provided from a recent penetration test to calculate CVSS scores to prioritize remediation. Which of the following metric groups would the analyst need to determine to get the overall scores? (Select THREE).

A.
Temporal
Answers
A.
Temporal
B.
Availability
Answers
B.
Availability
C.
Integrity
Answers
C.
Integrity
D.
Confidentiality
Answers
D.
Confidentiality
E.
Base
Answers
E.
Base
F.
Environmental
Answers
F.
Environmental
G.
Impact
Answers
G.
Impact
H.
Attack vector
Answers
H.
Attack vector
Suggested answer: A, E, F

Explanation:

The three metric groups that are needed to calculate CVSS scores are Base, Temporal, and Environmental. The Base metrics represent the intrinsic characteristics of a vulnerability that are constant over time and across user environments. The Temporal metrics represent the characteristics of a vulnerability that may change over time but not across user environments. The Environmental metrics represent the characteristics of a vulnerability that are relevant and unique to a particular user's environment. Verified

Reference:

https://nvd.nist.gov/vuln-metrics/cvss

https://www.first.org/cvss/specification-document

asked 02/10/2024
57 Milecross Lane Jodie
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first