PT0-003 · Question #208
Which of the following are valid reasons for including base, temporal, and environmental CVSS metrics in the findings section of a penetration testing report? (Select two).
The correct answer is B. Helping to prioritize remediation based on threat context D. Providing information on attack complexity and vector. The Common Vulnerability Scoring System (CVSS) provides a standardized way to evaluate the severity of security vulnerabilities. It includes: Base Metrics: Inherent characteristics of a vulnerability (e.g., attack vector, complexity). Temporal Metrics: Factors that change over…
Question
Which of the following are valid reasons for including base, temporal, and environmental CVSS metrics in the findings section of a penetration testing report? (Select two).
Options
- AProviding details on how to remediate vulnerabilities
- BHelping to prioritize remediation based on threat context
- CIncluding links to the proof-of-concept exploit itself
- DProviding information on attack complexity and vector
- EPrioritizing compliance information needed for an audit
- FAdding risk levels to each asset
How the community answered
(52 responses)- A6% (3)
- B90% (47)
- C2% (1)
- E2% (1)
Explanation
The Common Vulnerability Scoring System (CVSS) provides a standardized way to evaluate the severity of security vulnerabilities. It includes: Base Metrics: Inherent characteristics of a vulnerability (e.g., attack vector, complexity). Temporal Metrics: Factors that change over time (e.g., exploit availability). Environmental Metrics: Customization based on an organization's environment.
Topics
Community Discussion
No community discussion yet for this question.