H12-725_V4.0 · Question #41
Common Vulnerability Scoring System (CVSS) is a widely used open standard for vulnerability scoring and adopts a modular scoring system. Which of the following does not include?
The correct answer is D. Spatial dimensions. Spatial Dimensions (D) is correct because CVSS uses three metric groups - Base, Temporal, and Environmental - and "Spatial" is not one of them; it's a fabricated term with no place in the CVSS framework. Why the distractors are wrong: A (Environmental) is a real CVSS metric…
Question
Common Vulnerability Scoring System (CVSS) is a widely used open standard for vulnerability scoring and adopts a modular scoring system. Which of the following does not include?
Options
- AEnvironmental dimension
- BTime dimension
- CBasic dimensions
- DSpatial dimensions
How the community answered
(43 responses)- A5% (2)
- B2% (1)
- C14% (6)
- D79% (34)
Explanation
Spatial Dimensions (D) is correct because CVSS uses three metric groups - Base, Temporal, and Environmental - and "Spatial" is not one of them; it's a fabricated term with no place in the CVSS framework.
Why the distractors are wrong:
- A (Environmental) is a real CVSS metric group that lets organizations adjust scores based on their specific infrastructure and security controls, so it's included.
- B (Temporal/Time) is also a real CVSS metric group that accounts for factors that change over time, such as exploit code maturity and remediation availability.
- C (Base) is the foundational CVSS metric group capturing the intrinsic, constant characteristics of a vulnerability (attack vector, complexity, privileges required, etc.).
Memory tip: Remember the acronym BTE - Base, Temporal, Environmental. These are CVSS's three pillars. If an answer choice doesn't fit into BTE (like "Spatial"), it's the impostor.
Topics
Community Discussion
No community discussion yet for this question.