exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 243 discussion

Actual exam question from CompTIA's CAS-004
Question #: 243
Topic #: 1
[All CAS-004 Questions]

A security analyst is using data provided from a recent penetration test to calculate CVSS scores to prioritize remediation. Which of the following metric groups would the analyst need to determine to get the overall scores? (Choose three.)

  • A. Temporal
  • B. Availability
  • C. Integrity
  • D. Confidentiality
  • E. Base
  • F. Environmental
  • G. Impact
  • H. Attack vector
Show Suggested Answer Hide Answer
Suggested Answer: AEF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
8 months ago
Note: The "Base" metrics provide the initial score, while the "Temporal" and "Environmental" metrics adjust the score based on the current state and the specific context, respectively. Metrics like "Availability," "Integrity," and "Confidentiality" are components within the Base metric group, and "Impact" and "Attack vector" are specific aspects that contribute to calculating the Base score.
upvoted 2 times
...
suprman4485
1 year, 2 months ago
This makes me question all the Answers provided on this site. The answer is obviously AEF. However the site says its EGH?!?
upvoted 2 times
b49eb27
1 year ago
I think whoever originally provided the answers just guessed on everything, some of the answers are way off.
upvoted 2 times
...
...
Delab202
1 year, 3 months ago
Selected Answer: AEF
CVSS scores are calculated using a formula consisting of vulnerability-based metrics. A CVSS score is derived from scores in these three groups: Base, Temporal and Environmental. Scores range from zero to 10, with zero representing the least severe and 10 representing the most severe
upvoted 2 times
...
jan2134
2 years, 1 month ago
Selected Answer: AEF
A CVSS score is derived from scores in the following three metrics groups: Base Temporal Environmental See https://www.techtarget.com/searchsecurity/definition/CVSS-Common-Vulnerability-Scoring-System#:~:text=A%20CVSS%20score%20is%20derived%20from%20scores%20in,including%20its%20impact%20and%20environmental%20endurance%20over%20time.
upvoted 3 times
...
andre0994
2 years, 1 month ago
The Common Vulnerability Scoring System (CVSS) is a method used to supply a qualitative measure of severity. CVSS is not a measure of risk. CVSS consists of three metric groups: Base, Temporal, and Environmental. The Base metrics produce a score ranging from 0 to 10, which can then be modified by scoring the Temporal and Environmental metrics.
upvoted 1 times
...
[Removed]
2 years, 1 month ago
It's A, E, F.....I do this for a living....
upvoted 4 times
...
dragonflysecurity
2 years, 1 month ago
E. Base - This group includes metrics that are based on the characteristics of the vulnerability itself, such as the attack complexity, authentication requirements, and exploitability. G. Impact - This group includes metrics that measure the potential impact of the vulnerability, such as the scope of the impact, the severity of the consequences, and the affected assets. H. Attack vector - This group includes metrics that describe how the vulnerability is accessed or exploited, such as whether the attacker needs physical access or whether the vulnerability can be exploited remotely.
upvoted 1 times
...
WOM127
2 years, 1 month ago
Selected Answer: AEF
https://nvd.nist.gov/vuln-metrics/cvss#:~:text=CVSS%20consists%20of%20three%20metric,the%20Temporal%20and%20Environmental%20metrics.
upvoted 3 times
...
Cock
2 years, 1 month ago
Selected Answer: AEF
Base: This group contains the fundamental qualities of a vulnerability and includes metrics such as attack complexity and exploitability. Temporal: This group contains qualities that change over time like patch level, availability of exploit code, and remediation level. Environmental: This group contains qualities that are specific to an organization's environment such as business value and asset criticality.
upvoted 2 times
...
unBREAKable_Fs4
2 years, 1 month ago
A - Temporal E - Base F - Environmental From the CompTIA official CASP+ Cert Guide
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago