[Reporting and Communication]
Which of the following are valid reasons for including base, temporal, and environmental CVSS metrics in the findings section of a penetration testing report? (Select two).
The Common Vulnerability Scoring System (CVSS) provides a standardized way to evaluate the severity of security vulnerabilities. It includes:
Base Metrics: Inherent characteristics of a vulnerability (e.g., attack vector, complexity).
Temporal Metrics: Factors that change over time (e.g., exploit availability).
Environmental Metrics: Customization based on an organization's environment.
Correct answers:
Helping to prioritize remediation based on threat context (Option B):
CVSS scores help organizations prioritize vulnerabilities based on real-world impact.
The Environmental metric allows customization based on business risk.
Providing information on attack complexity and vector (Option D):
CVSS Base scores define attack complexity (e.g., low vs. high) and attack vector (e.g., network vs. physical).
This helps security teams understand how a vulnerability can be exploited.
Incorrect options:
Option A (Providing remediation details): CVSS does not include remediation steps; it only scores severity.
Option C (Proof-of-concept exploit links): CVSS scores are not based on specific exploits.
Option E (Compliance information): CVSS focuses on technical risk, not regulatory compliance.
Option F (Adding risk levels to assets): CVSS evaluates individual vulnerabilities, not asset risk classification.
Joanna
5 months agoKirk
5 months agoMarylin
5 months agoShonda
6 months agoGolda
6 months agoJaime
6 months agoLavonne
6 months agoShenika
7 months agoElmira
7 months agoLindsey
7 months agoWilda
7 months agoLili
7 months agoHeike
7 months agoLou
8 months agoJohnna
9 months agoCarylon
8 months agoDeeann
10 months agoSherrell
8 months agoParis
10 months agoElvera
8 months agoHelga
10 months agoLizbeth
10 months agoQuentin
10 months agoLeota
8 months agoFrederic
8 months agoGilma
10 months agoHillary
10 months agoCraig
10 months agoWai
11 months agoSherita
11 months ago