nerdexam
EC-Council

312-49 · Question #450

Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments…

The correct answer is A. CVE. CVE (Common Vulnerabilities and Exposures), maintained by MITRE Corporation and sponsored by CISA, is the authoritative public database for cataloging known cybersecurity vulnerabilities. Security researchers who discover potential new vulnerabilities submit them to MITRE for…

Submitted by chiamaka_o· Apr 18, 2026Network Forensics

Question

Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related. What organization should Frank submit the log to find out if it is a new vulnerability or not?

Options

  • ACVE
  • BIANA
  • CRIPE
  • DAPIPA

How the community answered

(26 responses)
  • A
    92% (24)
  • B
    4% (1)
  • C
    4% (1)

Explanation

CVE (Common Vulnerabilities and Exposures), maintained by MITRE Corporation and sponsored by CISA, is the authoritative public database for cataloging known cybersecurity vulnerabilities. Security researchers who discover potential new vulnerabilities submit them to MITRE for investigation, validation, and assignment of a CVE identifier. Frank should submit his logs to CVE/MITRE so they can determine if the suspicious behavior represents a previously unknown (zero-day) vulnerability and assign it an official CVE number if confirmed. The other options are unrelated: IANA manages internet number resources, RIPE NCC is a European regional internet registry, and APIPA is an automatic private IP addressing protocol - not an organization.

Topics

#CVE#Vulnerability identification#IDS logs#Vulnerability assessment

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice