About this interactive
CVSS v3.1 turns eight base metrics into one number between 0.0 and 10.0, and this drill makes you produce that number rather than read it off a scanner. Every item hands you a scenario, the CVSS vector string that describes it, the numeric weight each of its metrics carries, and the formula branch that applies — then takes the base score to one decimal place, or the severity rating, typed and graded exactly. The vectors are the ones the job actually produces: unauthenticated remote code execution at 9.8, memory disclosure at 7.5, local privilege escalation at 7.8, reflected cross-site scripting at 6.1, an evil-maid disk read at 4.6. Four of them have a CHANGED scope, which is where most hand-scored CVSS goes wrong: it uses a different impact formula, it raises the Privileges Required weights (Low becomes 0.68, not 0.62), and it multiplies the total by 1.08. Three items isolate one step so the arithmetic can be practised without the whole chain, and five drill the severity bands at their boundaries, because 3.9 and 4.0 are one tenth and two different remediation queues. Roundup is drilled deliberately: it takes a score UP to the next tenth, never to the nearest one, and six of the answers in this pool differ from what ordinary rounding would give. A miss shows the full derivation — ISS, impact, exploitability, the sum and the roundup — not just the number.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →