200-201 · Question #501
According to CVSS, which condition is required for attack complexity metrics?
The correct answer is A. man-in-the-middle attack. In the Common Vulnerability Scoring System (CVSS), the Attack Complexity (AC) metric measures the conditions that an attacker must overcome to exploit a vulnerability successfully. If an attack requires conditions beyond the attacker's control (e.g., requiring a…
Question
According to CVSS, which condition is required for attack complexity metrics?
Options
- Aman-in-the-middle attack
- Battackers altering any file
- Ccomplete loss of protection
- Dtotal loss of availability
How the community answered
(35 responses)- A86% (30)
- B3% (1)
- C6% (2)
- D6% (2)
Explanation
In the Common Vulnerability Scoring System (CVSS), the Attack Complexity (AC) metric measures the conditions that an attacker must overcome to exploit a vulnerability successfully. If an attack requires conditions beyond the attacker's control (e.g., requiring a Man-in-the-Middle (MitM) attack or specific system configurations), the attack complexity is considered high. This means an attacker needs additional conditions to be met before launching a successful attack.
Topics
Community Discussion
No community discussion yet for this question.