CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

A CVSS v3.1 vector reads: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. A client asks why the risk score is lower than expected given the high confidentiality, integrity, and availability impacts. Which base metric best explains this?

  1. AAttack Vector (AV:N)
  2. BUser Interaction (UI:N)
  3. CAttack Complexity (AC:H)
  4. DPrivileges Required (PR:N)
Show answer & explanation

Correct answer: C. Attack Complexity (AC:H)

Attack Complexity set to High (AC:H) means exploitation depends on conditions beyond the attacker's control, reducing exploit likelihood and lowering the overall score despite high impact metrics.

Why the other options are wrong

  • A. AV:N (Network) actually increases risk by making the vulnerability remotely reachable.
  • B. UI:N means no user interaction is required, which also increases risk.
  • D. PR:N means no privileges are needed, which increases risk rather than lowering it.

CVSS Attack Complexity (AC)

A CVSS base metric describing conditions beyond the attacker's control that must exist for successful exploitation.

  • AC:L (Low) = no special conditions needed, higher score
  • AC:H (High) = requires specific conditions, lower score
  • Distinct from Privileges Required and User Interaction metrics

Memory trick: 'A Cat Prowls Under Streetlights' = AV, AC, PR, UI, Scope

More Vulnerability Discovery and Analysis questions