- Home
- All questions
- Question 54
CompTIA Security+ study material · question 54 of 611
A team uses a vulnerability's CVSS score directly as its risk rating. Which factor does CVSS deliberately exclude that they must add themselves?
Show the answer
Answer: A. Regulatory exposure and monetary loss
CVSS measures severity. Regulatory, financial, safety and reputational factors are outside its scope and belong to the consumer.
Source: CVSS v4.0 specification (FIRST) — CVSS v4.0 Specification Document › Introduction