ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 12 - PT0-003 discussion

Report
Export

A penetration tester finished a security scan and uncovered numerous vulnerabilities on several hosts. Based on the targets' EPSS and CVSS scores, which of the following targets is the most likely to get attacked?

Host | CVSS | EPSS

Target 1 | 4 | 0.6

Target 2 | 2 | 0.3

Target 3 | 1 | 0.6

Target 4 | 4.5 | 0.4

A.
Target 1: CVSS Score = 4 and EPSS Score = 0.6
Answers
A.
Target 1: CVSS Score = 4 and EPSS Score = 0.6
B.
Target 2: CVSS Score = 2 and EPSS Score = 0.3
Answers
B.
Target 2: CVSS Score = 2 and EPSS Score = 0.3
C.
Target 3: CVSS Score = 1 and EPSS Score = 0.6
Answers
C.
Target 3: CVSS Score = 1 and EPSS Score = 0.6
D.
Target 4: CVSS Score = 4.5 and EPSS Score = 0.4
Answers
D.
Target 4: CVSS Score = 4.5 and EPSS Score = 0.4
Suggested answer: A

Explanation:

Based on the CVSS (Common Vulnerability Scoring System) and EPSS (Exploit Prediction Scoring System) scores, Target 1 is the most likely to get attacked.

CVSS:

Definition: CVSS provides a numerical score to represent the severity of a vulnerability, helping to prioritize the response based on the potential impact.

Score Range: Scores range from 0 to 10, with higher scores indicating more severe vulnerabilities.

EPSS:

Definition: EPSS estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days.

Score Range: EPSS scores range from 0 to 1, with higher scores indicating a higher likelihood of exploitation.

Analysis:

Target 1: CVSS = 4, EPSS = 0.6

Target 2: CVSS = 2, EPSS = 0.3

Target 3: CVSS = 1, EPSS = 0.6

Target 4: CVSS = 4.5, EPSS = 0.4

Target 1 has a moderate CVSS score and a high EPSS score, indicating it has a significant vulnerability that is quite likely to be exploited.

Pentest

Reference:

Vulnerability Prioritization: Using CVSS and EPSS scores to prioritize vulnerabilities based on severity and likelihood of exploitation.

Risk Assessment: Understanding the balance between impact (CVSS) and exploit likelihood (EPSS) to identify the most critical targets for remediation or attack.

By focusing on Target 1, which has a balanced combination of severity and exploitability, the penetration tester can address the most likely target for attacks based on the given scores.

asked 02/10/2024
SCOTTIE EASTER
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first