Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium
A security analyst is reviewing a vulnerability report for a critical web server. The report indicates a vulnerability with a Common Vulnerability Scoring System (CVSS) Base Score of 8.6. The analyst determines that the server is located in a highly secured internal network segment, accessible only by a few authorized administrators, and has robust intrusion prevention systems in place. Which CVSS metric category would be most directly influenced by these mitigating factors when calculating the final score?
- ABase Score
- BTemporal Score
- CEnvironmental Score
- DImpact Score
Show answer & explanationAnswer & explanation
Correct answer: C. Environmental Score
The Environmental Score in CVSS allows organizations to customize the severity of a vulnerability based on the specific security posture and importance of the affected system within their own environment. Factors like network segmentation and existing security controls directly influence this score.
Why the other options are wrong
- A. The Base Score is intrinsic to the vulnerability itself and does not change based on an organization's specific environment.
- B. The Temporal Score reflects changes over time, such as the availability of patches or exploit code, not the specific environmental context.
- D. Impact Score is a sub-component of the Base Score, reflecting the potential consequences of a successful exploit (e.g., confidentiality, integrity, availability), not environmental factors.
CVSS Environmental Score
The Environmental Score in CVSS measures the severity of a vulnerability based on the specific security posture and importance of the affected system within an organization's own environment.
- Customizes vulnerability severity for specific organizational contexts.
- Considers compensating controls and asset importance.
- Adjusts the Base Score to reflect real-world risk.
Memory trick: Base Time Environment, Impact's the Key.