nerdexam
Cisco

100-160 · Question #41

Which two basic metrics should be taken into consideration when assigning a severity to a vulnerability during an assessment? (Choose two.)

The correct answer is A. The likelihood that an adversary can and will exploit the vulnerability B. The impacts that an exploit of the vulnerability will have on the organization. When prioritizing vulnerabilities, assess both the likelihood of exploitation and the potential impact to the organization. Likelihood measures how easy or probable it is for an adversary to exploit the weakness, while impact measures the consequences to confidentiality…

Threats and Vulnerabilities

Question

Which two basic metrics should be taken into consideration when assigning a severity to a vulnerability during an assessment? (Choose two.)

Options

  • AThe likelihood that an adversary can and will exploit the vulnerability
  • BThe impacts that an exploit of the vulnerability will have on the organization
  • CThe time involved in choosing replacement software to replace older systems
  • DThe age of the hardware running the software that contains the vulnerability

How the community answered

(46 responses)
  • A
    89% (41)
  • C
    4% (2)
  • D
    7% (3)

Explanation

When prioritizing vulnerabilities, assess both the likelihood of exploitation and the potential impact to the organization. Likelihood measures how easy or probable it is for an adversary to exploit the weakness, while impact measures the consequences to confidentiality, integrity, and availability if exploitation occurs.

Topics

#vulnerability severity#CVSS#exploit likelihood#impact assessment

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice