312-50V13 · Question #585
A large organization has recently performed a vulnerability assessment using Nessus Professional, and the security team is now preparing the final report. They have identified a high- risk…
The correct answer is B. The total number of high, medium, and low-risk vulnerabilities detected throughout the network. Explanation Option B is correct because the total count of all vulnerabilities across the network is a high-level summary statistic that belongs in the executive summary or overall report overview - not in the detailed documentation for a specific vulnerability like XYZ. When…
Question
Options
- AProof of concept (PoC) of the vulnerability, if possible, to demonstrate its potential impact on the
- BThe total number of high, medium, and low-risk vulnerabilities detected throughout the network.
- CThe list of all affected systems within the organization that are susceptible to the identified
- DThe CVE ID of the vulnerability and its mapping to the vulnerability's name, XYZ.
How the community answered
(32 responses)- A3% (1)
- B72% (23)
- C16% (5)
- D9% (3)
Explanation
Explanation
Option B is correct because the total count of all vulnerabilities across the network is a high-level summary statistic that belongs in the executive summary or overall report overview - not in the detailed documentation for a specific vulnerability like XYZ. When documenting an individual vulnerability, the focus is exclusively on that vulnerability's specifics, not aggregate network-wide statistics.
- Option A is wrong because a Proof of Concept (PoC) is absolutely standard in detailed vulnerability documentation, as it demonstrates real-world exploitability and helps stakeholders understand the actual risk.
- Option C is wrong because listing all affected systems is a critical component of specific vulnerability documentation - it tells the remediation team exactly where to act.
- Option D is wrong because the CVE ID and name mapping is fundamental to vulnerability documentation, providing a standardized reference that links to patch databases, vendor advisories, and risk scoring (CVSS).
Memory Tip: Think of vulnerability documentation like a patient medical record - you document that patient's diagnosis, symptoms, and affected areas, not the total number of sick patients in the hospital. Summary numbers belong in the "hospital report," not the individual chart.
Topics
Community Discussion
No community discussion yet for this question.