exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 117 discussion

Actual exam question from CompTIA's CS0-003
Question #: 117
Topic #: 1
[All CS0-003 Questions]

A vulnerability analyst received a list of system vulnerabilities and needs to evaluate the relevant impact of the exploits on the business. Given the constraints of the current sprint, only three can be remediated. Which of the following represents the least impactful risk, given the CVSS3.1 base scores?

  • A. AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L - Base Score 6.0
  • B. AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L - Base Score 7.2
  • C. AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H - Base Score 6.4
  • D. AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L - Base Score 6.5
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BanesTech
Highly Voted 1 year ago
Selected Answer: D
The answer is D. A. Total Impact Score = C + I + A = 0.56 + 0.56 + 0.22 = 1.34 B. Total Impact Score = C + I + A = 0.56 + 0.56 + 0.22 = 1.34 C. Total Impact Score = C + I + A = 0.56 + 0.56 + 0.56 = 1.68 D. Total Impact Score = C + I + A = 0.22 + 0.22 + 0.22 = 0.66 Therefore, vulnerability D represents the least impactful risk, given the CVSS3.1 base scores, as it has the lowest total impact score.
upvoted 12 times
lilegg
11 months, 1 week ago
This is a legit explanation, the numbers don't lie.
upvoted 4 times
...
...
c83335b
Highly Voted 11 months, 4 weeks ago
Selected Answer: D
you only need to focus on the las three /C:L/I:L/A:L because is asking for the least impactful so basically is D.
upvoted 6 times
...
8f1fc75
Most Recent 6 months ago
If you ask GPT this, you'll get the wrong answer, since it just looks at the base score. The fact of the matter is D. has CIA - low/low/low, making it the least impactful overall.
upvoted 2 times
...
remmytaylor97
7 months ago
Selected Answer: A
the least impactful vulnerability as it has the lowest CVSS score, indicating that it’s harder to exploit and requires more conditions to be met compared to the others.
upvoted 1 times
...
f72cee9
8 months, 1 week ago
A: Although D has lower CIA impacts, its lower attack barriers (no privileges required, no user interaction, and scope change) make it more concerning. A represents a lower risk de to its higher barriers for exploitation, even though its base score is lower.
upvoted 1 times
...
Myfeedins479
9 months ago
Selected Answer: D
Can confirm that impact is composed of the confidentiality, integrity, and availability metrics per CompTIA CySA+ Study Guide: Exam CS0-003, Third Edition.
upvoted 3 times
...
nap61
9 months, 4 weeks ago
Selected Answer: A
"Which of the following represents the least impactful risk, GIVEN THE CVSS3.1 BASE SCORES?" Easy question, tricky is in the wording. Based in the score = 6.0. ;)
upvoted 2 times
...
LB54
10 months ago
Selected Answer: A
Considering the impact on confidentiality, integrity, and availability, Option A (Base Score 6.0) represents the least impactful risk if left unremediated. It has a moderate overall risk level. The other options have either higher availability impact or broader scope, making them riskier choices for prioritization. The difference between A & D lies in the privileges required and user interaction aspects. Option A requires higher privileges and user interaction, which could limit its exploitation. However, both options have similar overall risk levels.
upvoted 1 times
...
RiccardoBellitto
1 year ago
Selected Answer: D
The answer is D since they are asking about the least impactful (impact = CIA triad)
upvoted 1 times
...
glenndexter
1 year ago
Selected Answer: D
Comparing the impact metrics, option D has the lowest impact overall, as it has low scores for confidentiality, integrity, and availability. Therefore, option D represents the least impactful risk.
upvoted 2 times
...
jjkylin
1 year, 1 month ago
Selected Answer: D
Please note the key word "least impactful risk". The score doesn't represent the impact. The impact is only related to CIA metrics.
upvoted 2 times
...
Kmelaun
1 year, 1 month ago
Selected Answer: A
Agreed with section8santa, while D has greater CIA values, A is harder to exploit due to it's attack complexity, privileges and user interaction required. Making the it the one with the lowest base score, and the one we would worry about remediating after we remediate the first 3 vulnerabilities. We assume that the higher the base score, the more urgent it is to remediate, we look at other contributing factors when the base scores are the same to further make a decision but in this example, none of the base scores are the same.
upvoted 1 times
Kmelaun
12 months ago
After further investigation, D would be correct.
upvoted 4 times
...
...
jjkylin
1 year, 1 month ago
Selected Answer: D
See the CVSS 3.1 user guide. https://www.first.org/cvss/v3.1/user-guide 3.2. Confidentiality and Integrity, Versus Availability Impacts The Confidentiality and Integrity metrics refer to impacts that affect the data used by the service. For example, web content that has been maliciously altered, or system files that have been stolen. The Availability impact metric refers to the operation of the service. That is, the Availability metric speaks to the performance and operation of the service itself – not the availability of the data. Consider a vulnerability in an Internet service such as web, email, or DNS that allows an attacker to modify or delete all web files in a directory. The only impact is to Integrity, not Availability, as the web service is still functioning – it just happens to be serving back altered content.
upvoted 1 times
...
section8santa
1 year, 1 month ago
Selected Answer: A
This vulnerability, while having high impacts on confidentiality and integrity, has a lower impact on availability (A:L), requires high attack complexity, high privileges, and user interaction. This makes it less likely to be exploited compared to the others, thus representing the least impactful risk among the given options.
upvoted 2 times
...
bettyboo
1 year, 2 months ago
Selected Answer: D
D. because the score for CIA is L
upvoted 1 times
...
jspecht
1 year, 2 months ago
Selected Answer: A
A requires user interaction UI:R and yet the availability is low A:L making A a better choice than D or C.
upvoted 1 times
...
indyrckstar
1 year, 3 months ago
Selected Answer: D
Went with D due to CIA are all L.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago