nerdexam
Cisco

200-201 · Question #30

When you are researching a Windows operating system vulnerability (such as CVE-2016-7211), which organization can provide detailed information about the specific vulnerability?

The correct answer is C. National Institute of Standards and Technology (NIST). The National Institute of Standards and Technology (NIST) provides detailed information about vulnerabilities through its National Vulnerability Database (NVD).

Submitted by akirajp· Mar 6, 2026Security Policies and Procedures

Question

When you are researching a Windows operating system vulnerability (such as CVE-2016-7211), which organization can provide detailed information about the specific vulnerability?

Options

  • AInstitute of Electrical and Electronics Engineers (IEEE)
  • BControl Objectives for Information and Related Technologies (COBIT)
  • CNational Institute of Standards and Technology (NIST)
  • DInternational Organization for Standardization (ISO)

How the community answered

(30 responses)
  • B
    7% (2)
  • C
    90% (27)
  • D
    3% (1)

Why each option

The National Institute of Standards and Technology (NIST) provides detailed information about vulnerabilities through its National Vulnerability Database (NVD).

AInstitute of Electrical and Electronics Engineers (IEEE)

IEEE is known for setting standards for electrical and electronic engineering, not for maintaining a vulnerability database.

BControl Objectives for Information and Related Technologies (COBIT)

COBIT is a framework for IT governance and management, not a repository for specific vulnerability information.

CNational Institute of Standards and Technology (NIST)Correct

NIST operates the National Vulnerability Database (NVD), which is the U.S. government's repository of standards-based vulnerability management data, enriching CVEs with additional information like impact and exploitability scores.

DInternational Organization for Standardization (ISO)

ISO is an international standard-setting body that publishes various standards, but it does not maintain a database of specific software vulnerabilities.

Concept tested: Vulnerability Information Sources (NVD/CVE)

Source: https://nvd.nist.gov/

Topics

#vulnerability research#NIST#CVE

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice