312-50V12 · Question #192
During a recent vulnerability assessment of a major corporation's IT systems, the security team identified several potential risks. They want to use a vulnerability scoring system to quantify and…
The correct answer is B. Base metric represents the inherent qualities of a vulnerability. The question assesses understanding of the Common Vulnerability Scoring System (CVSS) and its metric types. It specifically asks to identify the most accurate statement regarding how CVSS measures vulnerability characteristics.
Question
Options
- ATemporal metric represents the inherent qualities of a vulnerability.
- BBase metric represents the inherent qualities of a vulnerability.
- CTemporal metric involves measuring vulnerabilities based on a specific environment or
- DEnvironmental metric involves the features that change during the lifetime of the vulnerability.
How the community answered
(59 responses)- A2% (1)
- B95% (56)
- D3% (2)
Why each option
The question assesses understanding of the Common Vulnerability Scoring System (CVSS) and its metric types. It specifically asks to identify the most accurate statement regarding how CVSS measures vulnerability characteristics.
Temporal metrics measure how a vulnerability's characteristics change over time due to factors like exploit code availability or the release of patches, rather than representing its inherent qualities.
CVSS Base metrics are designed to represent the intrinsic and unchanging qualities of a vulnerability, such as its exploitability and impact on confidentiality, integrity, and availability. These metrics provide a fundamental score that remains constant over time and across different user environments, reflecting the vulnerability's inherent severity.
Environmental metrics, not Temporal metrics, are used to adjust vulnerability scores based on the specific organizational context, security controls, and asset importance within a particular environment.
This statement describes the function of Temporal metrics, which account for changes in vulnerability features over its lifetime, making it incorrect for Environmental metrics.
Concept tested: CVSS Metric Types and Definitions
Source: https://www.first.org/cvss/v3.1/specification-document
Topics
Community Discussion
No community discussion yet for this question.