exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 298 discussion

Actual exam question from CompTIA's CS0-002
Question #: 298
Topic #: 1
[All CS0-002 Questions]

A customer notifies a security analyst that a web application is vulnerable to information disclosure. The analyst needs to indicate the severity of the vulnerability based on its CVSS score, which the analyst needs to calculate. When analyzing the vulnerability, the analyst realizes that for the attack to be successful, the Tomcat configuration file must be modified. Which of the following values should the security analyst choose when evaluating the CVSS score?

  • A. Network
  • B. Physical
  • C. Adjacent
  • D. Local
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
encxorblood
Highly Voted 2 years, 2 months ago
Selected Answer: D
When evaluating the CVSS score for a vulnerability that requires modifying the Tomcat configuration file, the security analyst should choose the "Local" value. Therefore, option D is the correct answer. CVSS (Common Vulnerability Scoring System) is a framework that provides a way to evaluate the severity of a vulnerability. CVSS uses a set of metrics to measure the potential impact of a vulnerability and assign it a score. The "Local" metric in CVSS measures the degree of access required to exploit the vulnerability. A "Local" vulnerability can only be exploited by an attacker who has physical access to the system or who has already compromised the system through a separate attack. In this scenario, modifying the Tomcat configuration file requires local access to the system and cannot be exploited remotely. Therefore, the appropriate metric to use when evaluating the CVSS score for this vulnerability is "Local."
upvoted 14 times
2Fish
2 years, 1 month ago
Yup, Agree... 100% D (local).
upvoted 1 times
...
...
Christopski
Most Recent 1 year, 6 months ago
This was on the exam
upvoted 1 times
...
skibby16
1 year, 7 months ago
Selected Answer: C
In this case, since the attack involves modifying the Tomcat configuration file, it indicates that the attacker needs to be in a network-adjacent position, meaning they need to have some level of network access or adjacency to the target system. Therefore, "Adjacent" is the appropriate choice for the "Access Vector" metric when evaluating the CVSS score for this vulnerability.
upvoted 1 times
...
kyky
1 year, 10 months ago
Selected Answer: C
C. Adjacent The "Adjacent" access complexity refers to an attacker who can directly connect to the target system, but they need to first gain access to an adjacent or neighboring system. In this scenario, the attacker needs to modify the Tomcat configuration file, indicating a level of access that is adjacent to the target web application
upvoted 2 times
...
yolylight
2 years, 1 month ago
Selected Answer: A
required specific configuration is in metric Attack Complexity,not Attack Vector
upvoted 1 times
...
absabs
2 years, 2 months ago
Selected Answer: D
I take articles from book; Local means shell access,either interactively orthrough a remote shell. Adjacent network refersto an attacking host withinthe same broadcastdomain (link-local) as thetarget. Network refers to a vulnerability that can beexploited from a remotenetwork (different subnet) So, i going with local.
upvoted 3 times
...
CatoFong
2 years, 3 months ago
Selected Answer: D
D. is correct
upvoted 1 times
...
gnnggnnggnng
2 years, 3 months ago
Selected Answer: D
The CVSS score determines the severity of a vulnerability based on the impact it has on the system and the ease of exploitation. In this scenario, the vulnerability can be exploited locally, meaning that the attacker has access to the target system and can directly modify the Tomcat configuration file. The CVSS score for Local attacks is higher compared to other types of attacks, so the security analyst should choose "Local" when evaluating the CVSS score.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago