200-201 · Question #30
When you are researching a Windows operating system vulnerability (such as CVE-2016-7211), which organization can provide detailed information about the specific vulnerability?
The correct answer is C. National Institute of Standards and Technology (NIST). The National Institute of Standards and Technology (NIST) provides detailed information about vulnerabilities through its National Vulnerability Database (NVD).
Question
When you are researching a Windows operating system vulnerability (such as CVE-2016-7211), which organization can provide detailed information about the specific vulnerability?
Options
- AInstitute of Electrical and Electronics Engineers (IEEE)
- BControl Objectives for Information and Related Technologies (COBIT)
- CNational Institute of Standards and Technology (NIST)
- DInternational Organization for Standardization (ISO)
How the community answered
(30 responses)- B7% (2)
- C90% (27)
- D3% (1)
Why each option
The National Institute of Standards and Technology (NIST) provides detailed information about vulnerabilities through its National Vulnerability Database (NVD).
IEEE is known for setting standards for electrical and electronic engineering, not for maintaining a vulnerability database.
COBIT is a framework for IT governance and management, not a repository for specific vulnerability information.
NIST operates the National Vulnerability Database (NVD), which is the U.S. government's repository of standards-based vulnerability management data, enriching CVEs with additional information like impact and exploitability scores.
ISO is an international standard-setting body that publishes various standards, but it does not maintain a database of specific software vulnerabilities.
Concept tested: Vulnerability Information Sources (NVD/CVE)
Source: https://nvd.nist.gov/
Topics
Community Discussion
No community discussion yet for this question.