exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 274 discussion

Actual exam question from CompTIA's CAS-004
Question #: 274
Topic #: 1
[All CAS-004 Questions]

Due to budget constraints, an organization created a policy that only permits vulnerabilities rated high and critical according to CVSS to be fixed or mitigated. A security analyst notices that many vulnerabilities that were previously scored as medium are now breaching higher thresholds. Upon further investigation, the analyst notices certain ratings are not aligned with the approved system categorization.

Which of the following can the analyst do to get a better picture of the risk while adhering to the organization’s policy?

  • A. Align the exploitability metrics to the predetermined system categorization.
  • B. Align the remediation levels to the predetermined system categorization.
  • C. Align the impact subscore requirements to the predetermined system categorization.
  • D. Align the attack vectors to the predetermined system categorization.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BiteSize
Highly Voted 1 year, 5 months ago
Selected Answer: C
The impact subscore measures how much damage an attacker could cause if they successfully exploited this vulnerability3. By aligning the impact subscore requirements to the predetermined system categorization, the security analyst can get a better picture of the risk while adhering to the organization’s policy.
upvoted 6 times
...
ewbafoow
Highly Voted 1 year, 7 months ago
Selected Answer: C
I interpret this as the Organization caring about impact. CVSS Impact scores are measure in Low, Medium, and High. If an attack vector's exploitability is High, but the Impact is low, budget consideration would tell me that it is irrelevant. But if the IMPACT is high to the business, it needs to be fixed.
upvoted 5 times
...
deeden
Most Recent 1 month ago
Selected Answer: C
Agree with C. Example of Misalignment: - A medium-severity vulnerability in a public-facing financial application (critical system) might be ignored under the organization's current policy, even though its exploitation could have significant consequences. - Similarly, a high-severity vulnerability in a low-criticality marketing system may be unnecessarily prioritized over issues in critical systems. The organization can align vulnerability prioritization with system categorization by weighting CVSS metrics according to the criticality of the affected system.
upvoted 1 times
...
Bright07
1 month, 1 week ago
Selected Answer: A
A. Align the exploitability metrics to the predetermined system categorization. Here's why: Exploitability metrics in the CVSS (Common Vulnerability Scoring System) take into account factors like how easily a vulnerability can be exploited. By aligning these metrics with the organization's predetermined system categorization, the analyst can adjust the ratings to reflect the specific threat environment, such as the system’s exposure or its criticality. This would help in adjusting the CVSS score to better fit the organization's risk assessment criteria while adhering to the policy of only addressing high and critical vulnerabilities. NOT C. because the impact sub score in CVSS focuses on the consequences of a vulnerability being exploited (e.g., confidentiality, integrity, availability). Aligning these with the system categorization may provide insight into the actual impact, but it doesn’t address the main issue of vulnerabilities breaching thresholds based on their exploitability.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago