Question: 9. In CVSS v. 3.1, while vulnerabilities are typically scored on the Base and Temporal metrics by the broader security community, the scoring on Environmental
9. In CVSS v. 3.1, while vulnerabilities are typically scored on the Base and Temporal metrics by the broader security community, the scoring on Environmental Metrics is to be done by analysts at the end-user organizations.
True or False
10. According to the CVSS v.3.1 specification, the Exploitability metrics reflect the ease and technical means by which the vulnerability can be exploited. That is, they represent characteristics of the thing that is vulnerable. CVSS v.3 refers to "the thing that is vulnerable" as:
The Impacted Component
The Vulnerable Component
The Base Component
The Environmental Component
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
