100-160 · Question #41
Which two basic metrics should be taken into consideration when assigning a severity to a vulnerability during an assessment? (Choose two.)
The correct answer is A. The likelihood that an adversary can and will exploit the vulnerability B. The impacts that an exploit of the vulnerability will have on the organization. When prioritizing vulnerabilities, assess both the likelihood of exploitation and the potential impact to the organization. Likelihood measures how easy or probable it is for an adversary to exploit the weakness, while impact measures the consequences to confidentiality…
Question
Which two basic metrics should be taken into consideration when assigning a severity to a vulnerability during an assessment? (Choose two.)
Options
- AThe likelihood that an adversary can and will exploit the vulnerability
- BThe impacts that an exploit of the vulnerability will have on the organization
- CThe time involved in choosing replacement software to replace older systems
- DThe age of the hardware running the software that contains the vulnerability
How the community answered
(46 responses)- A89% (41)
- C4% (2)
- D7% (3)
Explanation
When prioritizing vulnerabilities, assess both the likelihood of exploitation and the potential impact to the organization. Likelihood measures how easy or probable it is for an adversary to exploit the weakness, while impact measures the consequences to confidentiality, integrity, and availability if exploitation occurs.
Topics
Community Discussion
No community discussion yet for this question.