A CVE for a city hall AP requires physical console access to exploit. After recording the CVE, how should impact judgment differ from a remote wireless exploit?
Select an answer to reveal the explanation.
Short Explanation
Still log the CVE—but a bug that needs someone at the serial port is not the same fire drill as a remote wireless exploit. Preconditions change how hard you stomp on the city's risk pedal.
Full Explanation
After identifying a CVE, risk and impact analysis must consider exploit preconditions. Physical console-only flaws generally present different exposure than remotely reachable wireless exploits. Recording remains necessary; dismissing the CVE entirely or applying indiscriminate citywide shutdowns without context misreads impact analysis.