nerdexam
EC-Council

412-79V10 · Question #77

Russell, a penetration tester after performing the penetration testing, wants to create a report so that he can provide details of the testing process and findings of the vulnerabilities to the…

The correct answer is D. High. See the full explanation below for the reasoning.

Question

Russell, a penetration tester after performing the penetration testing, wants to create a report so that he can provide details of the testing process and findings of the vulnerabilities to the organization. Russell identified an SMB-based vulnerability and assigned a CVSS v3.0 rating, whereas the organization uses CVSS v2.0 ratings for grading the severity and risk level of identified vulnerabilities in the report. For a specific SMB-based vulnerability, Russell assigned a score of 8.0. What is the level of risk or of severity of the SMB vulnerability as per CVSS v3.0 for the assigned score?

Options

  • ACritical
  • BLow
  • CMedium
  • DHigh

How the community answered

(53 responses)
  • A
    9% (5)
  • B
    15% (8)
  • C
    4% (2)
  • D
    72% (38)

Community Discussion

No community discussion yet for this question.

Full 412-79V10 Practice