PT0-003 · Question #77
A penetration tester needs to evaluate the order in which the next systems will be selected for testing. Given the following output: Which of the following targets should the tester select next?
The correct answer is A. fileserver. Evaluation Criteria: CVSS (Common Vulnerability Scoring System): Indicates the severity of vulnerabilities, with higher scores representing more critical vulnerabilities. EPSS (Exploit Prediction Scoring System): Estimates the likelihood of a vulnerability being exploited in the
Question
A penetration tester needs to evaluate the order in which the next systems will be selected for testing. Given the following output:
Which of the following targets should the tester select next?
Exhibit
Options
- Afileserver
- Bhrdatabase
- Clegaldatabase
- Dfinancesite
How the community answered
(28 responses)- A79% (22)
- B4% (1)
- C4% (1)
- D14% (4)
Explanation
Evaluation Criteria: CVSS (Common Vulnerability Scoring System): Indicates the severity of vulnerabilities, with higher scores representing more critical vulnerabilities. EPSS (Exploit Prediction Scoring System): Estimates the likelihood of a vulnerability being exploited in the wild. hrdatabase: CVSS = 9.9, EPSS = 0.50 financesite: CVSS = 8.0, EPSS = 0.01 legaldatabase: CVSS = 8.2, EPSS = 0.60 fileserver: CVSS = 7.6, EPSS = 0.90 Selection Justification: fileserver has the highest EPSS score of 0.90, indicating a high likelihood of exploitation despite having a slightly lower CVSS score compared to other targets. This makes it a critical target for immediate testing to mitigate potential exploitation risks.
Topics
Community Discussion
No community discussion yet for this question.
