A vulnerability report shows a web application flaw with the vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N. Which statement best explains the base-score drivers?
Select an answer to reveal the explanation.
Short Explanation
CVSS is like a recipe: each metric adds or subtracts flavor, but you can taste the final score. High complexity, high privileges, and user interaction make the attack harder, so they pull the score down. Don't let a scary impact metric fool you—check the exploitability metrics first.
Full Explanation
CVSS base scores combine exploitability and impact. In a v4.0 vector, network access, no attack requirements, and high vulnerable-system impact push the score upward, while high attack complexity, high privileges required, passive user interaction, and no subsequent-system impact reduce it. The high confidentiality impact remains the strongest impact signal, but it does not override the reduced exploitability created by the harder-to-reach conditions. Network attack vector and no attack requirements are favorable to the attacker, so they raise rather than reduce the score. Saying high attack complexity has no effect ignores that it represents significant preconditions or environmental factors that make exploitation less reliable. Claiming low complexity, no privileges, and no interaction reduce the score reverses the metric polarity; those conditions make exploitation easier. Treating all impact metrics as elevating the score is also wrong because low or none impact values for integrity, availability, and subsequent systems pull the score down. Exam caveat: CVSS v4.0 separates vulnerable-system and subsequent-system impact, so do not apply v3.1 assumptions about scope or user interaction values. Operational check: Parse the vector into exploitability and impact groups, then compare the base score against any environmental score modifiers before prioritizing remediation.