nerdexam
CompTIA

CV0-004 · Question #119

An organization has been using an old version of an Apache Log4j software component in its critical software application. Which of the following should the organization use to calculate the severity…

The correct answer is B. CVSS. The Common Vulnerability Scoring System (CVSS) is what the organization should use to calculate the severity of the risk from using an old version of Apache Log4j software component. CVSS provides an open framework for communicating the characteristics and impacts of IT…

Security

Question

An organization has been using an old version of an Apache Log4j software component in its critical software application. Which of the following should the organization use to calculate the severity of the risk from using this component?

Options

  • ACWE
  • BCVSS
  • CCWSS
  • DCVE

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    94% (48)
  • C
    4% (2)

Explanation

The Common Vulnerability Scoring System (CVSS) is what the organization should use to calculate the severity of the risk from using an old version of Apache Log4j software component. CVSS provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.

Topics

#Vulnerability scoring#Risk assessment#CVSS#Software security

Community Discussion

No community discussion yet for this question.

Full CV0-004 Practice