Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 1 Question 103 Discussion

According to CVSS, what is attack complexity?
B) existing circumstances beyond the attacker's control to exploit the vulnerability
A) existing exploits available in the wild exploiting the vulnerability
C) number of actions an attacker should perform to exploit the vulnerability
D) number of patches available for certain attack mitigation and how complex the workarounds are

Cisco 200-201 Exam - Topic 1 Question 103 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 103
Topic #: 1
[All 200-201 Questions]

According to CVSS, what is attack complexity?

Show Suggested Answer Hide Answer
Suggested Answer: B

In the Common Vulnerability Scoring System (CVSS), attack complexity refers to the conditions beyond the attacker's control that must exist for the vulnerability to be successfully exploited.

This includes factors such as the need for user interaction, the presence of specific configurations, or network conditions that are not easily controlled by the attacker.

A high attack complexity means that these external factors make exploitation more difficult, while a low attack complexity indicates that fewer such conditions are required.


CVSS v3.1 Specifications Document

Understanding Attack Complexity in Vulnerability Assessments

Cybersecurity Frameworks and Metrics

Contribute your Thoughts:

0/2000 characters
Heike
9 months ago
Isn't it surprising how complex some vulnerabilities can be?
upvoted 0 times
...
Elke
9 months ago
I think it’s more about the circumstances affecting the attack.
upvoted 0 times
...
Michel
10 months ago
Wait, I thought it was about existing exploits?
upvoted 0 times
...
Angelo
10 months ago
Totally agree, it's all about the steps involved!
upvoted 0 times
...
Johnna
10 months ago
Attack complexity refers to how many actions an attacker needs to take to exploit a vulnerability.
upvoted 0 times
...
Leanna
10 months ago
I thought attack complexity was related to how many exploits are out there, but now I'm confused if that's really what A means.
upvoted 0 times
...
Delmy
11 months ago
I practiced a question similar to this, and I feel like attack complexity is about the existing conditions that affect the attack, which might be B again.
upvoted 0 times
...
Shalon
11 months ago
I remember something about the number of actions needed to exploit a vulnerability, which sounds like C, but I'm not completely sure.
upvoted 0 times
...
Aliza
11 months ago
I think attack complexity refers to the circumstances that make it harder for an attacker to exploit a vulnerability, so maybe it's B?
upvoted 0 times
...
Brandee
11 months ago
This seems straightforward. Attack complexity is about the number of actions the attacker needs to perform, so I'm going to go with option C.
upvoted 0 times
...
Justine
11 months ago
Okay, I remember learning about this in class. Attack complexity is about the existing circumstances beyond the attacker's control, so I'll select option B.
upvoted 0 times
...
Ashton
11 months ago
Hmm, I'm a bit confused on this one. I thought attack complexity had to do with the availability of existing exploits, but I'm not totally sure. I'll have to think this through carefully.
upvoted 0 times
...
Zana
11 months ago
I'm pretty sure attack complexity refers to the number of steps an attacker needs to take to exploit the vulnerability, so I'll go with option C.
upvoted 0 times
...
Lina
2 years ago
C is the clear choice here. Although, I do wonder if the exam committee has a dark sense of humor and is actually looking for 'the number of hackers required to successfully exploit the vulnerability' as the answer.
upvoted 0 times
...
Daisy
2 years ago
Ah, the age-old question of attack complexity. I'd say C is the way to go, unless the exam is trying to trick us. Better not fall for any quantum entanglement shenanigans!
upvoted 0 times
Mariko
1 year ago
I'm not sure, but D sounds plausible, number of patches available for certain attack mitigation and how complex the workarounds are.
upvoted 0 times
...
Launa
1 year ago
I believe it's A, existing exploits available in the wild exploiting the vulnerability.
upvoted 0 times
...
Willow
2 years ago
I'm leaning towards B, existing circumstances beyond the attacker's control to exploit the vulnerability.
upvoted 0 times
...
Valentin
2 years ago
I think it's C, the number of actions an attacker should perform to exploit the vulnerability.
upvoted 0 times
...
...
Hyman
2 years ago
D? Nah, that's way too specific. I'm going with C. Seems like the best fit for attack complexity.
upvoted 0 times
...
Josephine
2 years ago
Hmm, I was leaning towards B, but C makes sense too. Gotta love these tricky CVSS questions!
upvoted 0 times
Gracia
2 years ago
Yeah, that makes sense. It's all about how complex the attack process is.
upvoted 0 times
...
Goldie
2 years ago
I think it's C, the number of actions an attacker should perform to exploit the vulnerability.
upvoted 0 times
...
...
Tamekia
2 years ago
I think it's C. The number of actions an attacker should perform to exploit the vulnerability seems like the most logical answer.
upvoted 0 times
Amber
2 years ago
Actually, it's B. Existing circumstances beyond the attacker's control to exploit the vulnerability.
upvoted 0 times
...
Jess
2 years ago
I think it's C. The number of actions an attacker should perform to exploit the vulnerability seems like the most logical answer.
upvoted 0 times
...
...
Shanice
2 years ago
That makes sense, it's about how difficult it is for the attacker to carry out the attack.
upvoted 0 times
...
Mignon
2 years ago
I think it's the number of actions an attacker should perform to exploit the vulnerability.
upvoted 0 times
...
Shanice
2 years ago
What is attack complexity according to CVSS?
upvoted 0 times
...

Save Cancel