CAS-004 Security Operations Practice Question
A security analyst is reviewing a CVSS score for a vulnerability that affects a critical server. The base score is 7.5, but the analyst needs to adjust for the environment. Which TWO of the following are valid CVSS environmental metrics that can modify the score? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modified Attack Vector (MAV)
Modified Attack Vector (MAV) is a valid CVSS environmental metric because the Environmental metric group includes Modified versions of the Base exploitability metrics (MAV, MAC, MPR, MUI, MS), allowing the analyst to re-score the Attack Vector based on how the vulnerable server is actually reachable in their environment. Modified Privileges Required (MPR) is likewise a valid environmental metric, since it lets the analyst adjust the privilege level an attacker needs in their specific deployment rather than using the Base PR value. Both MAV and MPR are explicitly part of the CVSS Environmental metric group and therefore can modify the overall score. By contrast, Exploit Code Maturity (ECM) belongs to the Temporal metric group, not the Environmental group, so it is not an environmental metric. Attack Vector (AV) and Privileges Required (PR) are Base metrics, which describe the intrinsic vulnerability and cannot themselves be used to adjust for the environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploit Code Maturity (ECM)
Why it's wrong here
Exploit Code Maturity belongs to the CVSS temporal metric group, reflecting the current state of exploit tooling rather than organisation-specific impact. It is tempting because exploit availability changes over time, and ECM would be correct when adjusting a score for the evolving threat landscape rather than the analyst's own environment.
- ✗
Privileges Required (PR)
Why it's wrong here
Privileges Required is a base metric describing the attacker's pre-exploitation access level; it is fixed in the base score and cannot be reweighted for a specific environment. It is tempting because privilege context feels environment-specific, and PR would be the correct answer if the question asked which base metric to review.
- ✓
Modified Attack Vector (MAV)
Why this is correct
Modified Attack Vector (MAV) is a valid CVSS environmental metric that adjusts the base Attack Vector to reflect how the vulnerability is actually exploitable in the organisation's environment, directly satisfying the stem's requirement to tailor the 7.5 base score.
- ✗
Attack Vector (AV)
Why it's wrong here
Attack Vector is a base metric capturing how the vulnerability is exploited (network, adjacent, local, physical); it is not adjustable through environmental scoring. It is tempting because exposure varies by deployment, and AV would be correct if the analyst were scoring the vulnerability itself rather than tailoring it to a given environment.
- ✓
Modified Privileges Required (MPR)
Why this is correct
Modified Privileges Required is a genuine CVSS environmental metric, letting the analyst override the base Privileges Required value to reflect the actual privilege level an attacker needs in this specific environment, so the 7.5 base score is recalculated against real deployment conditions.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.