In CVSS, which metric represents the inherent qualities of a vulnerability?

Prepare for the Certified Ethical Hacker Version 11 Exam with a comprehensive test featuring flashcards and multiple choice questions, each accompanied by hints and explanations to ensure a thorough understanding. Ace your ethical hacking exam with confidence!

Multiple Choice

In CVSS, which metric represents the inherent qualities of a vulnerability?

Explanation:
In CVSS, the Base metrics capture the vulnerability’s inherent characteristics—the attributes that define the vulnerability itself and don’t depend on when or where it exists. These cover how it can be exploited (attack vector, attack complexity, privileges required, user interaction), whether the impact changes when the vulnerability’s scope expands (scope), and the direct effects on confidentiality, integrity, and availability. Because these properties are intrinsic to the vulnerability, they remain constant across different environments and times. Temporal metrics adjust the score for factors that can change over time, like exploit code maturity and remediation status, while Environmental metrics tailor the score to a specific deployment’s needs and controls. Remediation is not a CVSS metric. So, the metric representing the vulnerability’s inherent qualities is the Base metric.

In CVSS, the Base metrics capture the vulnerability’s inherent characteristics—the attributes that define the vulnerability itself and don’t depend on when or where it exists. These cover how it can be exploited (attack vector, attack complexity, privileges required, user interaction), whether the impact changes when the vulnerability’s scope expands (scope), and the direct effects on confidentiality, integrity, and availability. Because these properties are intrinsic to the vulnerability, they remain constant across different environments and times. Temporal metrics adjust the score for factors that can change over time, like exploit code maturity and remediation status, while Environmental metrics tailor the score to a specific deployment’s needs and controls. Remediation is not a CVSS metric. So, the metric representing the vulnerability’s inherent qualities is the Base metric.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy