ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 275 - CS0-003 discussion

Report
Export

A company has decided to expose several systems to the internet, The systems are currently available internally only. A security analyst is using a subset of CVSS3.1 exploitability metrics to prioritize the vulnerabilities that would be the most exploitable when the systems are exposed to the internet. The systems and the vulnerabilities are shown below:

Which of the following systems should be prioritized for patching?

A.
brown
Answers
A.
brown
B.
grey
Answers
B.
grey
C.
blane
Answers
C.
blane
D.
sullivan
Answers
D.
sullivan
Suggested answer: C

Explanation:

The system ''blane'' with the vulnerability name ''snakedoctor'' should be prioritized for patching as it has a network attack vector (AV:N), low attack complexity (AC:L), and high availability (A:H). These metrics indicate that it would be relatively easy to exploit this vulnerability over the internet, and the system is highly available.

Reference: According to the CVSS v3.1 Specification Document, the exploitability metrics for CVSS are Attack Vector, Attack Complexity, Privileges Required, User Interaction, and Scope. These metrics measure how the vulnerability is accessed, the complexity of the attack, and the level of interaction and privileges required to exploit the vulnerability. The image shows a table with the values of these metrics for each system and vulnerability. Based on these values, the system ''blane'' has the highest exploitability score, as it has the most favorable conditions for an attacker. The other systems have either a lower attack vector, higher attack complexity, or lower availability, which make them less exploitable. Therefore, the system ''blane'' should be patched first.

asked 02/10/2024
David Brun
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first