nerdexam
(ISC)2

CGRC · Question #650

A SCAP specification for communicating the characteristics of vulnerabilities and measuring their relative severity. Response:

The correct answer is A. Common Vulnerability Scoring System (CVSS). The Common Vulnerability Scoring System (CVSS) is a SCAP specification used to communicate the characteristics of software vulnerabilities and assign them a numerical score, reflecting their severity and helping prioritize responses. It provides a standardized method for assessin

Assessment/Audit of Security and Privacy Controls

Question

A SCAP specification for communicating the characteristics of vulnerabilities and measuring their relative severity. Response:

Options

  • ACommon Vulnerability Scoring System (CVSS)
  • BContinuity of Operations Plan (COOP)
  • CDisaster Recovery Plan (DRP)
  • DCommon Vulnerability and Exposures (CVE)

How the community answered

(35 responses)
  • A
    91% (32)
  • C
    3% (1)
  • D
    6% (2)

Why each option

The Common Vulnerability Scoring System (CVSS) is a SCAP specification used to communicate the characteristics of software vulnerabilities and assign them a numerical score, reflecting their severity and helping prioritize responses. It provides a standardized method for assessing vulnerability impact.

ACommon Vulnerability Scoring System (CVSS)Correct

The Common Vulnerability Scoring System (CVSS) is a widely used, open industry standard for assessing the severity of computer system security vulnerabilities and is a key component of the SCAP framework for communicating vulnerability characteristics.

BContinuity of Operations Plan (COOP)

A Continuity of Operations Plan (COOP) is a plan for maintaining essential functions during a disruption, not a vulnerability scoring system.

CDisaster Recovery Plan (DRP)

A Disaster Recovery Plan (DRP) outlines procedures for recovering IT infrastructure after a disaster, not for scoring vulnerabilities.

DCommon Vulnerability and Exposures (CVE)

Common Vulnerabilities and Exposures (CVE) provides a dictionary of publicly known cybersecurity vulnerabilities, but it does not define a system for scoring their severity; that is CVSS's role.

Concept tested: CVSS definition and purpose

Source: https://www.first.org/cvss/

Topics

#CVSS#Vulnerability Management#Risk Assessment#SCAP

Community Discussion

No community discussion yet for this question.

Full CGRC Practice