Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is reviewing a CVSS score for a vulnerability that affects a critical server. The base score is 7.5, but the analyst needs to adjust for the environment. Which TWO of the following are valid CVSS environmental metrics that can modify the score? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modified Attack Vector (MAV)

Modified Attack Vector (MAV) is a valid CVSS environmental metric because the Environmental metric group includes Modified versions of the Base exploitability metrics (MAV, MAC, MPR, MUI, MS), allowing the analyst to re-score the Attack Vector based on how the vulnerable server is actually reachable in their environment. Modified Privileges Required (MPR) is likewise a valid environmental metric, since it lets the analyst adjust the privilege level an attacker needs in their specific deployment rather than using the Base PR value. Both MAV and MPR are explicitly part of the CVSS Environmental metric group and therefore can modify the overall score. By contrast, Exploit Code Maturity (ECM) belongs to the Temporal metric group, not the Environmental group, so it is not an environmental metric. Attack Vector (AV) and Privileges Required (PR) are Base metrics, which describe the intrinsic vulnerability and cannot themselves be used to adjust for the environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exploit Code Maturity (ECM)

    Why it's wrong here

    Exploit Code Maturity belongs to the CVSS temporal metric group, reflecting the current state of exploit tooling rather than organisation-specific impact. It is tempting because exploit availability changes over time, and ECM would be correct when adjusting a score for the evolving threat landscape rather than the analyst's own environment.

  • ✗

    Privileges Required (PR)

    Why it's wrong here

    Privileges Required is a base metric describing the attacker's pre-exploitation access level; it is fixed in the base score and cannot be reweighted for a specific environment. It is tempting because privilege context feels environment-specific, and PR would be the correct answer if the question asked which base metric to review.

  • ✓

    Modified Attack Vector (MAV)

    Why this is correct

    Modified Attack Vector (MAV) is a valid CVSS environmental metric that adjusts the base Attack Vector to reflect how the vulnerability is actually exploitable in the organisation's environment, directly satisfying the stem's requirement to tailor the 7.5 base score.

  • ✗

    Attack Vector (AV)

    Why it's wrong here

    Attack Vector is a base metric capturing how the vulnerability is exploited (network, adjacent, local, physical); it is not adjustable through environmental scoring. It is tempting because exposure varies by deployment, and AV would be correct if the analyst were scoring the vulnerability itself rather than tailoring it to a given environment.

  • ✓

    Modified Privileges Required (MPR)

    Why this is correct

    Modified Privileges Required is a genuine CVSS environmental metric, letting the analyst override the base Privileges Required value to reflect the actual privilege level an attacker needs in this specific environment, so the 7.5 base score is recalculated against real deployment conditions.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.