100-160 · Question #22
Which metric is used in risk assessment to evaluate the severity of a vulnerability?
The correct answer is A. CVSS score. CVSS (Common Vulnerability Scoring System) is the industry-standard metric for quantifying vulnerability severity, producing a numerical score from 0–10 that reflects factors like exploitability, impact, and scope - making it the correct tool for risk assessment. Why the…
Question
Which metric is used in risk assessment to evaluate the severity of a vulnerability?
Options
- ACVSS score
- BResponse time
- CThreat level index
- DPacket loss percentage
How the community answered
(37 responses)- A86% (32)
- B3% (1)
- C8% (3)
- D3% (1)
Explanation
CVSS (Common Vulnerability Scoring System) is the industry-standard metric for quantifying vulnerability severity, producing a numerical score from 0–10 that reflects factors like exploitability, impact, and scope - making it the correct tool for risk assessment.
Why the distractors are wrong:
- B. Response time measures network or system performance, not vulnerability severity.
- C. Threat level index is not a standardized security metric - it's a distractor borrowing plausible-sounding terminology.
- D. Packet loss percentage is a network quality metric with no direct role in vulnerability assessment.
Memory tip: Think "CVSS = Criticality Value for Security Scoring." The acronym itself signals its purpose - if you're scoring a vulnerability's danger, you want CVSS. Any answer involving network performance (response time, packet loss) is almost always wrong for risk/vulnerability questions.
Topics
Community Discussion
No community discussion yet for this question.