nerdexam
Cisco

200-201 · Question #501

According to CVSS, which condition is required for attack complexity metrics?

The correct answer is A. man-in-the-middle attack. In the Common Vulnerability Scoring System (CVSS), the Attack Complexity (AC) metric measures the conditions that an attacker must overcome to exploit a vulnerability successfully. If an attack requires conditions beyond the attacker's control (e.g., requiring a…

Submitted by kavita_s· Mar 6, 2026Security Concepts

Question

According to CVSS, which condition is required for attack complexity metrics?

Options

  • Aman-in-the-middle attack
  • Battackers altering any file
  • Ccomplete loss of protection
  • Dtotal loss of availability

How the community answered

(35 responses)
  • A
    86% (30)
  • B
    3% (1)
  • C
    6% (2)
  • D
    6% (2)

Explanation

In the Common Vulnerability Scoring System (CVSS), the Attack Complexity (AC) metric measures the conditions that an attacker must overcome to exploit a vulnerability successfully. If an attack requires conditions beyond the attacker's control (e.g., requiring a Man-in-the-Middle (MitM) attack or specific system configurations), the attack complexity is considered high. This means an attacker needs additional conditions to be met before launching a successful attack.

Topics

#CVSS#vulnerability assessment#attack complexity#man-in-the-middle

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice