nerdexam
Cisco

100-160 · Question #22

Which metric is used in risk assessment to evaluate the severity of a vulnerability?

The correct answer is A. CVSS score. CVSS (Common Vulnerability Scoring System) is the industry-standard metric for quantifying vulnerability severity, producing a numerical score from 0–10 that reflects factors like exploitability, impact, and scope - making it the correct tool for risk assessment. Why the…

Threats and Vulnerabilities

Question

Which metric is used in risk assessment to evaluate the severity of a vulnerability?

Options

  • ACVSS score
  • BResponse time
  • CThreat level index
  • DPacket loss percentage

How the community answered

(37 responses)
  • A
    86% (32)
  • B
    3% (1)
  • C
    8% (3)
  • D
    3% (1)

Explanation

CVSS (Common Vulnerability Scoring System) is the industry-standard metric for quantifying vulnerability severity, producing a numerical score from 0–10 that reflects factors like exploitability, impact, and scope - making it the correct tool for risk assessment.

Why the distractors are wrong:

  • B. Response time measures network or system performance, not vulnerability severity.
  • C. Threat level index is not a standardized security metric - it's a distractor borrowing plausible-sounding terminology.
  • D. Packet loss percentage is a network quality metric with no direct role in vulnerability assessment.

Memory tip: Think "CVSS = Criticality Value for Security Scoring." The acronym itself signals its purpose - if you're scoring a vulnerability's danger, you want CVSS. Any answer involving network performance (response time, packet loss) is almost always wrong for risk/vulnerability questions.

Topics

#CVSS#Vulnerability Scoring#Risk Assessment#Severity Metrics

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice