Study. uk . com
  1. Home
  2. All questions
  3. Question 578

CompTIA Security+ study material · question 578 of 611

A flaw is exploitable only when a non-default option is enabled. How should the Base metrics be scored?

  1. At half the severity it would otherwise receive
  2. As though the system is in the configuration the attack requires
  3. The vulnerability cannot be scored
  4. As though the option is disabled, since that is the default
Show the answer

Answer: B. As though the system is in the configuration the attack requires

Specific configurations do not reduce the Base assessment; the vulnerable system is scored in the state that enables the attack.

Source: CVSS v4.0 specification (FIRST) — CVSS v4.0 Specification Document › Base Metrics

Challenge yourself on this topic → Study as cards