CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
An analyst calculates a CVSS v3.1 Base Score of 8.9 for a newly discovered vulnerability in a network appliance. According to the official CVSS v3.1 qualitative severity rating scale, which severity label should be assigned to this finding?
- AHigh
- BCritical
- CLow
- DMedium
Show answer & explanationAnswer & explanation
Correct answer: A. High
CVSS v3.1 defines the High severity band as scores from 7.0 to 8.9. A score of 9.0–10.0 is required to reach Critical, so 8.9 falls just under that threshold and is rated High.
Why the other options are wrong
- B. Critical requires 9.0–10.0; 8.9 does not qualify.
- C. Low covers 0.1–3.9, far below 8.9.
- D. Medium covers 4.0–6.9, well below 8.9.
CVSS Qualitative Severity Rating
CVSS v3.1 maps numeric base scores to five qualitative labels used for reporting and prioritization.
- None = 0.0
- Low = 0.1–3.9, Medium = 4.0–6.9
- High = 7.0–8.9, Critical = 9.0–10.0
Memory trick: None-Low-Med-High-Crit climbs like a ladder toward 10