Walk the string left to right. The first four Base metrics describe how hard the flaw is to reach and trigger: Attack Vector (network, adjacent, local, physical), Attack Complexity (low or high), Privileges Required (none, low, high) and User Interaction. Each step away from the network, toward needing a login or a user's click, makes exploitation harder. The impact metrics come after.
Who fills in which group matters for scenario questions. The vendor or a vulnerability database publishes the Base metrics. Threat metrics come from intelligence about exploitation. Environmental metrics are yours: you raise or lower them to reflect how important the asset is and what controls already protect it. That is how CVSS takes your environment into account, and why a Base score alone can mislead.
Two v4.0 changes catch people who learned v3.1. Attack Requirements (AT) records conditions on the target that the attacker does not control, such as a race condition that has to be won or a non-default setting that has to be on; Attack Complexity now covers only what the attacker must do to get past protections like address randomization. User Interaction gains two levels: Passive, where the user only has to do something ordinary, like opening a page, and Active, where the user has to take a deliberate step, like dismissing a warning or running a file.
Threat metrics and EPSS can look like the same idea. Exploit Maturity records what is already known about exploitation, while EPSS predicts the chance of it in the next 30 days. The CVSS vs EPSS guide shows how the exam combines them.