A penetration tester finishes a security scan and uncovers numerous vulnerabilities on several hosts. Based on the targets' EPSS (Exploit Prediction Scoring System) and CVSS (Common Vulnerability Scoring System) scores, which of the following targets is the most likely to get attacked?
The EPSS (Exploit Prediction Scoring System) estimates how likely a vulnerability is to be exploited. Higher EPSS scores indicate a higher likelihood of exploitation.
Option A (Target 1) :
EPSS 0.6 (60% chance of exploitation)
CVSS 4 (Medium severity)
Best candidate since it has the highest likelihood of exploitation.
Option B (Target 2) : EPSS 0.3 (30%) is lower, making it less likely to be attacked.
Option C (Target 3) : EPSS 0.6 is high, but CVSS 1 is very low, meaning the vulnerability is not critical.
Option D (Target 4) : CVSS 4.5 is higher, but EPSS 0.4 is lower, meaning attackers are less likely to exploit it.
Reference: CompTIA PenTest+ PT0-003 Official Guide -- Vulnerability Prioritization with EPSS & CVSS
Currently there are no comments in this discussion, be the first to comment!