nerdexam
CompTIA

CAS-005 · Question #320

After a vendor identified a recent vulnerability, a severity score was assigned to the vulnerability. A notification was also publicly distributed. Which of the following would most likely include inf

The correct answer is A. CVE. A CVE (Common Vulnerabilities and Exposures) entry is a public identifier for a known cybersecurity vulnerability, which typically includes detailed information and often references remediation steps.

Submitted by amina.ke· Mar 6, 2026Security Operations

Question

After a vendor identified a recent vulnerability, a severity score was assigned to the vulnerability. A notification was also publicly distributed. Which of the following would most likely include information regarding the vulnerability and the recommended remediation steps?

Options

  • ACVE
  • BCVSS
  • CCCE
  • DCPE

How the community answered

(48 responses)
  • A
    90% (43)
  • B
    2% (1)
  • C
    6% (3)
  • D
    2% (1)

Why each option

A CVE (Common Vulnerabilities and Exposures) entry is a public identifier for a known cybersecurity vulnerability, which typically includes detailed information and often references remediation steps.

ACVECorrect

A CVE (Common Vulnerabilities and Exposures) is a list of publicly disclosed cybersecurity vulnerabilities. Each CVE entry includes an identifier (e.g., CVE-2023-12345), a description of the vulnerability, and often links to advisories, vendor patches, or other resources that contain recommended remediation steps and severity scores.

BCVSS

CVSS (Common Vulnerability Scoring System) is a standardized method for rating the severity of a vulnerability, assigning a score, but it does not itself include the detailed vulnerability description or remediation steps, rather it quantifies the impact.

CCCE

CCE (Common Configuration Enumeration) is a list of common configuration issues and best practices, not specifically for new vulnerabilities and their remediation.

DCPE

CPE (Common Platform Enumeration) is a structured naming scheme for IT systems, platforms, and packages, used for identifying product versions, not for detailing vulnerabilities or remediation.

Concept tested: Vulnerability management standards, threat intelligence

Source: https://www.cve.org/About/Terms

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice