200-201 exam dumps

200-201 practice question 70 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 70

Select 3

A cybersecurity analyst is reviewing a vulnerability report that includes a CVSS score of 9.8. The report identifies the vulnerability as having a high impact on confidentiality, integrity, and availability. Additionally, it states that the vulnerability can be exploited remotely without authentication. Based on the CVSS scoring system, which terms correctly describe key characteristics of this vulnerability?

  1. A

    Attack Vector: Network

  2. B

    Attack Complexity: High

  3. C

    Privileges Required: None

  4. D

    Confidentiality Impact: High

  5. E

    User Interaction: Required

Show answer and explanation

Correct answers: A, C, D

Explanation

This question tests your understanding of CVSS terms by applying them to a scenario. CVSS metrics such as Attack Vector, Privileges Required, and Confidentiality Impact are key to accurately describing a vulnerability's characteristics. In this case, the vulnerability's exploitability (network-based, no required privileges) and its impact (high confidentiality impact) align with the correct CVSS terms.

  • A. Correct.

    The 'Attack Vector: Network' term indicates that the vulnerability can be exploited remotely, as mentioned in the scenario. This matches the CVSS definition for this metric.

  • B. Incorrect.

    The 'Attack Complexity: High' term is incorrect because the scenario does not indicate that exploitation requires special conditions or significant effort, which would instead suggest 'Attack Complexity: Low.'

  • C. Correct.

    The 'Privileges Required: None' term is correct because the scenario explicitly states that the vulnerability can be exploited without authentication, aligning with this CVSS metric description.

  • D. Correct.

    The 'Confidentiality Impact: High' term is correct because the scenario mentions a high impact on confidentiality, integrity, and availability, which matches the CVSS definition of high impact.

  • E. Incorrect.

    The 'User Interaction: Required' term is incorrect because the scenario does not mention any action from a user being necessary for the exploitation, which would instead indicate 'User Interaction: None.'

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam