A recent zero-day vulnerability is being actively exploited, requires no user interaction or privilege escalation, and has a
significant impact to confidentiality and integrity but not to availability. Which of the following CVE metrics would be most
accurate for this zero-day threat?
A. CVSS:31/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:K/A:L Most Voted
B. CVSS:31/AV:K/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
C. CVSS:31/AV:N/AC:L/PR:N/UI:H/S:U/C:L/I:N/A:H
D. CVSS:31/AV:L/AC:L/PR:R/UI:R/S:U/C:H/I:L/A:H
Correct Answer: A
Community vote distribution
A (95%) B (5%)
Comments
12a n y Highly Voted 11 months, 1 week ago
Has anyone taken the exam recently ?
upvoted 12 times
Wolf541 7 months, 2 weeks ago
I am planning on taking it early February, I will let everyone know how it goes.
upvoted 3 times
longnh87 4 months, 3 weeks ago
Hi, did you do well? Do these Questions Help?
upvoted 1 times
Baz10 6 months ago
How'd it go?
upvoted 1 times
, S enseless84 6 months, 1 week ago
Me, and this questions are not valid anymore. Had only 20 questions from this pool, and yeah i have all 416. Had 3 PBQs which
are not listed in this Questions and on other ones they changed IPs not the same as here. Not sure if they have refund but i
need one.
Advising anyone who will attend it to wait for new question update.
upvoted 4 times
Xpert777 10 months ago
Why can't we see all of the reviews?
upvoted 3 times
testta k er1984 9 months, 4 weeks ago
you neeed to be a paid member. I guess
upvoted 4 times
Xpert777 9 months, 2 weeks ago
if you go into wayback machine, search up exam topics, and find the cysa 002 exam, go to january 4th snapshot, and you'll
see what I'm talking about. General review of the exam before even beginning the questions. I just want it back. Can the
admins bring it back?
upvoted 5 times
Mr_TooTs Highly Voted 11 months, 2 weeks ago
Selected Answer: A
Going for A here, reasons being following (Put ** around the secrtions in the text):
Vector - Network (Not Asked about)
Complexity - Low (Not Asked about)
Privileges Required - None (A recent zero-day vulnerability is being actively exploited, requires no user interaction or
**privilege escalation**)
User interaction - None (A recent zero-day vulnerability is being actively exploited, **requires no user interaction** or privilege
escalation)
Scope -Unchanged (Not Asked about)
Confidentiality - High (has a significant impact to **confidentiality** and integrity but not to availability)
Integrity - K ? - Typo Perhaps?
Availability - Low (has a significant impact to confidentiality and integrity but not to **availability**)
upvoted 11 times
YogiT 7 months, 2 weeks ago
K-Kill, according to AI.
upvoted 1 times
deeden 1 year, 11 months ago
There is no "K" value for Integrity (I) and Attack Vector (AV), but A has the least amount to unlikely value. Reference:
https://www.first.org/cvss/calculator/3.1
upvoted 2 times
j ig g u 12 Most Recent 1 month, 1 week ago
has anyone taken exam ,are the questions from here?
upvoted 2 times
Da rionAllen2 1 month ago
I believe this selection is accurate for the most part. However be sure to understand why each question is correct/incorrect and
you'll be fine.
, upvoted 1 times
f90ecff 4 months ago
Selected Answer: A
I scored an 800 last week on this material. Good Luck all!
upvoted 6 times
12a ny 3 months, 4 weeks ago
using this question bank?
upvoted 1 times
zecomeia _007 9 months, 1 week ago
Selected Answer: A
I pass my brothers and systers with this exam, but many question doesn't is here. You need Study more. The BBQ show the way,
but the way change in all time, because the question changes in every moment, but this exam is very very good for you.
upvoted 1 times
KAIjunn 9 months, 3 weeks ago
A Other options include incorrect values for Attack Vector, Privileges Required, or the Impact metrics, making A the best fit.
upvoted 1 times
S ta blished 9 months, 3 weeks ago
Selected Answer: A
I took my exam today and passed with a score of 821! Many of the questions here appeared on the exam exactly as they were.
There were 69 questions in total, including 3 PBQs. One PBQ involved ping and nmap commands, while the other PBQs were
new but straightforward to understand and answer.
upvoted 8 times
ma ggie22 10 months, 1 week ago
Selected Answer: A
I just cleared my exam yesterday and I should say that only 30% from this dump came out. I had 5 PBQs and only the Cyber Kill
chain from this dump was on the PBQ section. I had 71 Questions and the first 40 questions are new. Btw I passed with 797
score.
upvoted 7 times
Orbitus 10 months ago
Did you finish all CSO-300 questions here before the exam? I have mine next Saturday and wouldn't mind any help and
direction you can throw my way. Thanks.
upvoted 1 times
ma ggie22 9 months, 4 weeks ago
I have a contributor access here. You'd better review the cso-002 as well, because they get some questions from there too.
Find this PBQ from SurePass. "The developers recently deployed new code to three web servers. A daffy automated external
device scan
report shows server vulnerabilities that are failure items according to PCI DSS". I had this one as well.
upvoted 3 times
Orbitus 9 months, 3 weeks ago
Thanks. I cleared it on Saturday. A bit of a brain fog as most of the questions were unexpected. The PBQs were diabolic.
CSAP achieved.
upvoted 1 times
12a ny 9 months, 2 weeks ago
were most of the questions from here?
upvoted 1 times
Uncle_Lucifer 11 months, 3 weeks ago
Selected Answer: A
, Selected Answer: A
No privilege is squired. Option B has privilege that makes it completely wrong.
Now option A should have had I:H but it is I:K.
The impact is not high, but at least not low, but it should be high. I now believe A is the best choice ignore by B selection
earlier.
upvoted 2 times
Uncle_Lucifer 1 year, 11 months ago
Also option B has user interaction, while A dosent. Answer is definitely A.
B has 2 wrongs while a has a slight wrong.
upvoted 1 times
CyberJa ck a l 11 months, 3 weeks ago
Correct answer is A as the UI (User Interaction) criteria specifies N for none.
upvoted 1 times
ussliberty 1 year, 8 months ago
K is not a possilbe value, yet it appears in A and B
H is not a possible value for UI, yet it appears in C
R is not a possible value for PR, yet it appears in D
So every statement contains invalid outputs.
The statement tells us the following are true. Therefore, A is the most correct answer.
PR=N
UI=N
C=H
I=H
A=/=H
upvoted 6 times
Cuk ur 1 year, 11 months ago
Selected Answer: A
K is typo, it's H.
upvoted 4 times
Uncle_Lucifer 1 year, 11 months ago
Selected Answer: B
Answer is B.
Significant impact to C and I (confidentially and integrity) so both should be high. But in A option only C was high while I was K
, not H.
But overall the choices looked screwed. CompTIA exam writers are something in the making
upvoted 1 times
Uncle_Lucifer 1 year, 11 months ago
Both A and B are not accurate. B has the best CIA setup while A has the best vector and privilege setup. This is word. Could be
A or B depending on what criteria is more important
upvoted 1 times
nma p_k ing_22 2 years ago
Selected Answer: B
For the given scenario of a recent zero-day vulnerability that is actively exploited, requires no user interaction or privilege
escalation, and has a significant impact on confidentiality and integrity but not on availability, the most accurate CVE metrics
would be:
B. CVSS:31/AV:K/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
upvoted 1 times
k morda lv 1 year, 11 months ago
If requires no user interer is A