CompTIA CySA+ (CS0-003) — Question 483
An older CVE with a vulnerability score of 7.1 was elevated to a score of 9.8 due to a widely available exploit being used to deliver ransomware. Which of the following factors would an analyst most likely communicate as the reason for this escalation?
Answer options
- A. Scope
- B. Weaponization
- C. CVSS
- D. Asset value
Correct answer: B
Explanation
The correct answer is B, Weaponization, as it relates to the development of an exploit that can actively be used to carry out attacks, such as delivering ransomware. The other options do not specifically address the impact of an exploit being available and actively used, which is crucial in determining the increase in the vulnerability score.