CAS-005 · Question #425
Due to budget constraints, an organization created a policy that only permits vulnerabilities rated high and critical according to CVSS to be fixed or mitigated. A security analyst notices that many v
Sign in or unlock CAS-005 to reveal the answer and full explanation for question #425. The question stem and answer options stay visible for context.
Question
Due to budget constraints, an organization created a policy that only permits vulnerabilities rated high and critical according to CVSS to be fixed or mitigated. A security analyst notices that many vulnerabilities that were previously scored as medium are now breaching higher thresholds. Upon further investigation, the analyst notices certain ratings are not aligned with the approved system categorization. Which of the following can the analyst do to get a better picture of the risk while adhering to the organization’s policy?
Options
- AAlign the exploitability metrics to the predetermined system categorization.
- BAlign the remediation levels to the predetermined system categorization.
- CAlign the impact subscore requirements to the predetermined system categorization.
- DAlign the attack vectors to the predetermined system categorization.
Unlock CAS-005 to see the answer
You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.