Which CVSS metric component is used to reflect the impact of a vulnerability based on the specific environment of an organization?
The environmental metric group modifies the base score using factors unique to the organisation's deployment, such as modified attack vector, confidentiality, integrity and availability requirements. It therefore reflects impact within a specific environment, exactly the constraint the question specifies.
Why this answer
The Environmental metric in CVSS adjusts the Base score to reflect the specific environment of an organization, including factors like modified attack vector, confidentiality, integrity, and availability requirements. It is the component explicitly designed to capture organization-specific impact.
Exam trap
CAS-005 often tests the confusion between Temporal metrics (time-based changes) and Environmental metrics (organization-specific context), causing candidates to pick Temporal when the question mentions the organization's environment.
How to eliminate wrong answers
Option A is wrong because Attack Vector is a Base metric that describes how the vulnerability is exploited (network, adjacent, local, physical) and is not environment-specific. Option B is wrong because Temporal metrics reflect characteristics that change over time, such as exploit code maturity, remediation level, and report confidence — not the organization's environment. Option D is wrong because Base metrics represent the intrinsic characteristics of the vulnerability that are constant across environments.