CCNP Security 350-701 SCOR Practice Test 4

CCNP Security 350-701 SCOR Practice Test 4 (Hard) - CVSSv3 Scoring and Vulnerability Management

CISCO CCNP Security Exam Logo

1 / 10

In CVSSv3, which metric group reflects characteristics of the vulnerability itself that do not change over time or across different deployment environments?

2 / 10

Which CVSSv3 Base metric captures how much access an attacker requires to the target system before exploiting a vulnerability, such as network-reachable versus requiring local access?

3 / 10

Two vulnerabilities have identical Base scores, but one has a publicly available, weaponized exploit while the other has none. Which CVSSv3 metric group would appropriately reflect this difference?

4 / 10

Which CVSSv3 Environmental metric allows an organization to adjust a vulnerability's effective severity score based on how critical the affected asset's confidentiality, integrity, or availability is to that specific organization?

5 / 10

Which prioritization approach reflects a mature vulnerability management practice, rather than patching strictly in order of CVSSv3 Base score alone?

6 / 10

Which CVSSv3 Base metric reflects whether successful exploitation requires the attacker to have any prior authenticated access or privileges on the target system?

7 / 10

A vulnerability's CVSSv3 Scope metric is marked as 'Changed.' What does this indicate about the vulnerability's potential impact?

8 / 10

Which vulnerability management practice would most directly reduce the window of exposure for a newly disclosed, actively exploited vulnerability affecting a business-critical, internet-facing server?

9 / 10

Which statement correctly describes the relationship between a CVE identifier and a CVSS score?

10 / 10

Which combination of factors would justify treating a vulnerability with a moderate CVSSv3 Base score as a higher operational priority than its Base score alone suggests?

Your score is

The average score is 0%

0%