nerdexam
CompTIA

CAS-005 · Question #286

A security analyst is using data provided from a recent penetration test to calculate CVSS scores to prioritize remediation. Which of the following metric groups would the analyst need to determine to

The correct answer is A. Temporal E. Base F. Environmental. The Common Vulnerability Scoring System (CVSS) v3.1 uses three metric groups to calculate overall scores: Base, Temporal, and Environmental. Base (E): Mandatory metrics assessing exploitability (e.g., attack vector) and impact (confidentiality, integrity, availability). Temporal

Submitted by carter_n· Mar 6, 2026Governance, Risk, and Compliance

Question

A security analyst is using data provided from a recent penetration test to calculate CVSS scores to prioritize remediation. Which of the following metric groups would the analyst need to determine to get the overall scores? (Select three).

Options

  • ATemporal
  • BAvailability
  • CIntegrity
  • DConfidentiality
  • EBase
  • FEnvironmental
  • GImpact
  • HAttack vector

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    7% (2)
  • D
    3% (1)

Explanation

The Common Vulnerability Scoring System (CVSS) v3.1 uses three metric groups to calculate overall scores: Base, Temporal, and Environmental. Base (E): Mandatory metrics assessing exploitability (e.g., attack vector) and impact (confidentiality, integrity, availability). Temporal (A): Optional metrics reflecting the current state of the vulnerability (e.g., exploit availability, remediation level). Environmental (F): Optional metrics tailoring the score to the organization's context (e.g., security

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice