CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
A CVSS v3.1 vector reads: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. A client asks why the risk score is lower than expected given the high confidentiality, integrity, and availability impacts. Which base metric best explains this?
- AAttack Vector (AV:N)
- BUser Interaction (UI:N)
- CAttack Complexity (AC:H)
- DPrivileges Required (PR:N)
Show answer & explanationAnswer & explanation
Correct answer: C. Attack Complexity (AC:H)
Attack Complexity set to High (AC:H) means exploitation depends on conditions beyond the attacker's control, reducing exploit likelihood and lowering the overall score despite high impact metrics.
Why the other options are wrong
- A. AV:N (Network) actually increases risk by making the vulnerability remotely reachable.
- B. UI:N means no user interaction is required, which also increases risk.
- D. PR:N means no privileges are needed, which increases risk rather than lowering it.
CVSS Attack Complexity (AC)
A CVSS base metric describing conditions beyond the attacker's control that must exist for successful exploitation.
- AC:L (Low) = no special conditions needed, higher score
- AC:H (High) = requires specific conditions, lower score
- Distinct from Privileges Required and User Interaction metrics
Memory trick: 'A Cat Prowls Under Streetlights' = AV, AC, PR, UI, Scope