Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium
A security analyst is reviewing a vulnerability scan report for a critical production server. The report indicates a missing security patch for the operating system that could lead to remote code execution. However, the server is isolated on a segmented network with no direct internet access and is protected by multiple layers of firewalls. Which CVSS metric should the analyst adjust to reflect this reduced exposure?
- APrivileges Required (PR)
- BUser Interaction (UI)
- CAttack Complexity (AC)
- DAttack Vector (AV)
Show answer & explanationAnswer & explanation
Correct answer: D. Attack Vector (AV)
The Attack Vector (AV) metric considers the path by which an attacker can exploit the vulnerability. Since the server is isolated and protected by firewalls, the network accessibility required for exploitation is significantly reduced, warranting an adjustment to this metric.
Why the other options are wrong
- A. Privileges Required (PR) describes the level of privileges an attacker needs to exploit the vulnerability, which is not affected by network segmentation.
- B. User Interaction (UI) indicates whether a user must be involved for the vulnerability to be exploited, which is unrelated to network isolation.
- C. Attack Complexity (AC) relates to the conditions beyond the attacker's control required for exploitation, not network isolation.
CVSS Attack Vector (AV)
A CVSS metric that describes the remoteness of an attack, indicating the path an attacker takes to exploit a vulnerability.
- Can be Network, Adjacent, Local, or Physical.
- Network (N) is the most severe, Physical (P) is the least.
- Reflects how accessible the vulnerable component is.
Memory trick: CIA's Availability and Attack Vector's Complexity Require User Privileges for Scope.