312-49 · Question #450
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments…
The correct answer is A. CVE. CVE (Common Vulnerabilities and Exposures), maintained by MITRE Corporation and sponsored by CISA, is the authoritative public database for cataloging known cybersecurity vulnerabilities. Security researchers who discover potential new vulnerabilities submit them to MITRE for…
Question
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?
Options
- ACVE
- BIANA
- CRIPE
- DAPIPA
How the community answered
(26 responses)- A92% (24)
- B4% (1)
- C4% (1)
Explanation
CVE (Common Vulnerabilities and Exposures), maintained by MITRE Corporation and sponsored by CISA, is the authoritative public database for cataloging known cybersecurity vulnerabilities. Security researchers who discover potential new vulnerabilities submit them to MITRE for investigation, validation, and assignment of a CVE identifier. Frank should submit his logs to CVE/MITRE so they can determine if the suspicious behavior represents a previously unknown (zero-day) vulnerability and assign it an official CVE number if confirmed. The other options are unrelated: IANA manages internet number resources, RIPE NCC is a European regional internet registry, and APIPA is an automatic private IP addressing protocol - not an organization.
Topics
Community Discussion
No community discussion yet for this question.