Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA Exam PT0-003 Topic 3 Question 25 Discussion

Actual exam question for CompTIA's PT0-003 exam
Question #: 25
Topic #: 3
[All PT0-003 Questions]

[Reporting and Communication]

Which of the following are valid reasons for including base, temporal, and environmental CVSS metrics in the findings section of a penetration testing report? (Select two).

Show Suggested Answer Hide Answer
Suggested Answer: B, D

The Common Vulnerability Scoring System (CVSS) provides a standardized way to evaluate the severity of security vulnerabilities. It includes:

Base Metrics: Inherent characteristics of a vulnerability (e.g., attack vector, complexity).

Temporal Metrics: Factors that change over time (e.g., exploit availability).

Environmental Metrics: Customization based on an organization's environment.

Correct answers:

Helping to prioritize remediation based on threat context (Option B):

CVSS scores help organizations prioritize vulnerabilities based on real-world impact.

The Environmental metric allows customization based on business risk.


Providing information on attack complexity and vector (Option D):

CVSS Base scores define attack complexity (e.g., low vs. high) and attack vector (e.g., network vs. physical).

This helps security teams understand how a vulnerability can be exploited.

Incorrect options:

Option A (Providing remediation details): CVSS does not include remediation steps; it only scores severity.

Option C (Proof-of-concept exploit links): CVSS scores are not based on specific exploits.

Option E (Compliance information): CVSS focuses on technical risk, not regulatory compliance.

Option F (Adding risk levels to assets): CVSS evaluates individual vulnerabilities, not asset risk classification.

Contribute your Thoughts:

Craig
3 days ago
I believe D is also important as it provides information on attack complexity.
upvoted 0 times
...
Wai
9 days ago
I agree with Sherita, those metrics can help prioritize remediation efforts.
upvoted 0 times
...
Sherita
11 days ago
I think A and B are valid reasons for including those metrics.
upvoted 0 times
...

Save Cancel