CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy

An analyst calculates a CVSS v3.1 Base Score of 8.9 for a newly discovered vulnerability in a network appliance. According to the official CVSS v3.1 qualitative severity rating scale, which severity label should be assigned to this finding?

  1. AHigh
  2. BCritical
  3. CLow
  4. DMedium
Show answer & explanation

Correct answer: A. High

CVSS v3.1 defines the High severity band as scores from 7.0 to 8.9. A score of 9.0–10.0 is required to reach Critical, so 8.9 falls just under that threshold and is rated High.

Why the other options are wrong

  • B. Critical requires 9.0–10.0; 8.9 does not qualify.
  • C. Low covers 0.1–3.9, far below 8.9.
  • D. Medium covers 4.0–6.9, well below 8.9.

CVSS Qualitative Severity Rating

CVSS v3.1 maps numeric base scores to five qualitative labels used for reporting and prioritization.

  • None = 0.0
  • Low = 0.1–3.9, Medium = 4.0–6.9
  • High = 7.0–8.9, Critical = 9.0–10.0

Memory trick: None-Low-Med-High-Crit climbs like a ladder toward 10

More Vulnerability Management questions