nerdexam
CompTIA

CAS-005 · Question #463

A security administrator needs to develop a remediation plan to address a large number of vulnerability scan results. Which of the following should the administrator use to determine the…

The correct answer is C. CVSS. The Common Vulnerability Scoring System (CVSS) provides a standardized severity score for each vulnerability, reflecting its potential impact and exploitability. By sorting your scan results by CVSS score, focusing first on the highest-severity (e.g., critical and high) issues…

Submitted by paula_co· Mar 6, 2026Governance, Risk, and Compliance

Question

A security administrator needs to develop a remediation plan to address a large number of vulnerability scan results. Which of the following should the administrator use to determine the vulnerabilities that should be addressed first?

Options

  • ACPE
  • BCCE
  • CCVSS
  • DCVE

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    89% (16)

Explanation

The Common Vulnerability Scoring System (CVSS) provides a standardized severity score for each vulnerability, reflecting its potential impact and exploitability. By sorting your scan results by CVSS score, focusing first on the highest-severity (e.g., critical and high) issues, you ensure your remediation plan targets the most dangerous vulnerabilities before lower-risk ones.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice