[Reporting and Communication]
Which of the following are valid reasons for including base, temporal, and environmental CVSS metrics in the findings section of a penetration testing report? (Select two).
The Common Vulnerability Scoring System (CVSS) provides a standardized way to evaluate the severity of security vulnerabilities. It includes:
Base Metrics: Inherent characteristics of a vulnerability (e.g., attack vector, complexity).
Temporal Metrics: Factors that change over time (e.g., exploit availability).
Environmental Metrics: Customization based on an organization's environment.
Correct answers:
Helping to prioritize remediation based on threat context (Option B):
CVSS scores help organizations prioritize vulnerabilities based on real-world impact.
The Environmental metric allows customization based on business risk.
Providing information on attack complexity and vector (Option D):
CVSS Base scores define attack complexity (e.g., low vs. high) and attack vector (e.g., network vs. physical).
This helps security teams understand how a vulnerability can be exploited.
Incorrect options:
Option A (Providing remediation details): CVSS does not include remediation steps; it only scores severity.
Option C (Proof-of-concept exploit links): CVSS scores are not based on specific exploits.
Option E (Compliance information): CVSS focuses on technical risk, not regulatory compliance.
Option F (Adding risk levels to assets): CVSS evaluates individual vulnerabilities, not asset risk classification.
Joanna
4 months agoKirk
4 months agoMarylin
4 months agoShonda
4 months agoGolda
4 months agoJaime
5 months agoLavonne
5 months agoShenika
5 months agoElmira
5 months agoLindsey
5 months agoWilda
6 months agoLili
6 months agoHeike
6 months agoLou
6 months agoJohnna
8 months agoCarylon
7 months agoDeeann
8 months agoSherrell
7 months agoParis
8 months agoElvera
7 months agoHelga
8 months agoLizbeth
9 months agoQuentin
9 months agoLeota
7 months agoFrederic
7 months agoGilma
8 months agoHillary
8 months agoCraig
9 months agoWai
9 months agoSherita
9 months ago