Valid 210-255 Dumps shared by EduDump.com for Helping Passing 210-255 Exam! EduDump.com now offer the newest 210-255 exam dumps, the EduDump.com 210-255 exam questions have been updated and answers have been corrected get the newest EduDump.com 210-255 dumps with Test Engine here:
Which CVSSv3 Attack Vector metric value requires the attacker to physically touch or manipulate the vulnerable component?
Correct Answer: B
Explanation: Attack Vector (AV): This metric reflects the context by which vulnerability exploitation is possible. This metric value and the base score will correlate with an attacker's proximity to a vulnerable component. The score will be higher the more remote (logically and physically) an attacker is from the vulnerable component. Local: Exploiting the vulnerability requires either physical access to the target or a local (shell) account on the target. Adjacent: Exploiting the vulnerability requires access to the local network of the target, and cannot be performed across an OSI Layer 3 boundary. Network: The vulnerability is exploitable from remote networks. Such a vulnerability is often termed "remotely exploitable," and can be thought of as an attack being exploitable one or more network hops away, such as across Layer 3 boundaries from routers. Physical: A vulnerability exploitable with physical access requires the attacker to physically touch or manipulate the vulnerable component.
Recent Comments (The most recent comments are at the top.)
idiot - Nov 12, 2018
User CCNA - you could not be more wrong. Stop confusing everyone and just research your answers before spouting rubbish. William is quite correct. See below for the differences between local and physical.
Local (L) A vulnerability exploitable with Local access means that the vulnerable component is not bound to the network stack, and the attacker's path is via read/write/execute capabilities. In some cases, the attacker may be logged in locally in order to exploit the vulnerability, otherwise, she may rely on User Interaction to execute a malicious file.
Physical (P) A vulnerability exploitable with Physical access requires the attacker to physically touch or manipulate the vulnerable component. Physical interaction may be brief (e.g. evil maid attack [1]) or persistent. An example of such an attack is a cold boot attack which allows an attacker to access to disk encryption keys after gaining physical access to the system, or peripheral attacks such as Firewire/USB Direct Memory Access attacks.
Recent Comments (The most recent comments are at the top.)
User CCNA - you could not be more wrong. Stop confusing everyone and just research your answers before spouting rubbish. William is quite correct. See below for the differences between local and physical.
Local (L) A vulnerability exploitable with Local access means that the vulnerable component is not bound to the network stack, and the attacker's path is via read/write/execute capabilities. In some cases, the attacker may be logged in locally in order to exploit the vulnerability, otherwise, she may rely on User Interaction to execute a malicious file.
Physical (P) A vulnerability exploitable with Physical access requires the attacker to physically touch or manipulate the vulnerable component. Physical interaction may be brief (e.g. evil maid attack [1]) or persistent. An example of such an attack is a cold boot attack which allows an attacker to access to disk encryption keys after gaining physical access to the system, or peripheral attacks such as Firewire/USB Direct Memory Access attacks.
There's a difference between physically access and physically touch so the answer is B
Reference: https://www.first.org/cvss/calculator/3.0
The answer is A