[Security Architecture]
A security analyst is using data provided from a recent penetration test to calculate CVSS scores to prioritize remediation. Which of the following metric groups would the analyst need to determine to get the overall scores? (Select three).
The Common Vulnerability Scoring System (CVSS) v3.1 uses three metric groups to calculate overall scores:Base,Temporal, andEnvironmental.
Base (E):Mandatory metrics assessing exploitability (e.g., attack vector) and impact (confidentiality, integrity, availability).
Temporal (A):Optional metrics reflecting the current state of the vulnerability (e.g., exploit availability, remediation level).
Environmental (F):Optional metrics tailoring the score to the organization's context (e.g., security requirements).
B, C, D (Availability, Integrity, Confidentiality):These are subcomponents of the Base Impact metrics, not standalone groups.
G (Impact):A categorywithin Base, not a group.
H (Attack vector):A single Base metric, not a group.
Gail
18 hours agoDana
6 days agoPaulina
11 days agoChauncey
16 days agoJannette
21 days agoFidelia
27 days agoLavina
1 month agoPrecious
1 month agoAnnice
1 month agoJanet
2 months agoFranklyn
2 months agoBrittni
2 months agoJanet
2 months agoLisha
3 months agoDevora
3 months agoClaribel
3 months agoLaurel
3 months agoRoxane
2 months agoFannie
2 months ago