Study. uk . com
  1. Home
  2. All questions
  3. Question 129

CompTIA Security+ study material · question 129 of 611

An analyst wants to lower a base score because the flaw was found through a difficult internal audit rather than being publicly known. Why is this wrong?

  1. Discovery method belongs in the Threat metrics
  2. Internal findings are always scored higher
  3. Base scores may only be set by the vendor
  4. Metrics are scored assuming the attacker has perfect knowledge of the vulnerability
Show the answer

Answer: D. Metrics are scored assuming the attacker has perfect knowledge of the vulnerability

How the flaw was found is outside CVSS. Obscurity is not credited in the score.

Source: CVSS v4.0 specification (FIRST) — CVSS v4.0 Specification Document › Assessment

Challenge yourself on this topic → Study as cards