Study. uk . com
  1. Home
  2. All questions
  3. Question 54

CompTIA Security+ study material · question 54 of 611

A team uses a vulnerability's CVSS score directly as its risk rating. Which factor does CVSS deliberately exclude that they must add themselves?

  1. Regulatory exposure and monetary loss
  2. The affected component's version
  3. Attack complexity
  4. Privileges required
Show the answer

Answer: A. Regulatory exposure and monetary loss

CVSS measures severity. Regulatory, financial, safety and reputational factors are outside its scope and belong to the consumer.

Source: CVSS v4.0 specification (FIRST) — CVSS v4.0 Specification Document › Introduction

Challenge yourself on this topic → Study as cards