nerdexam
(ISC)2

SSCP · Question #1077

A standardized list of the most common security weaknesses and exploits is the __________.

The correct answer is C. CVE - Common Vulnerabilities and Exposures. The Common Vulnerabilities and Exposures (CVE) system is a standardized list that identifies and describes publicly known cybersecurity vulnerabilities and exploits.

Submitted by hassan_iq· Apr 18, 2026Security Concepts and Practices

Question

A standardized list of the most common security weaknesses and exploits is the __________.

Options

  • ASANS Top 10
  • BCSI/FBI Computer Crime Study
  • CCVE - Common Vulnerabilities and Exposures
  • DCERT Top 10

How the community answered

(24 responses)
  • B
    4% (1)
  • C
    88% (21)
  • D
    8% (2)

Why each option

The Common Vulnerabilities and Exposures (CVE) system is a standardized list that identifies and describes publicly known cybersecurity vulnerabilities and exploits.

ASANS Top 10

The SANS Top 10 refers to a specific list of the most critical web application security risks, not a general standardized list of all common security weaknesses.

BCSI/FBI Computer Crime Study

The CSI/FBI Computer Crime Study was an annual report detailing trends and statistics related to computer crime, not a list of specific vulnerabilities.

CCVE - Common Vulnerabilities and ExposuresCorrect

CVE (Common Vulnerabilities and Exposures) provides a common lexicon for publicly known information security vulnerabilities, assigning each a unique identifier, description, and public references. This standardization allows for effective sharing and tracking of security weaknesses across various security products and services.

DCERT Top 10

While CERT (Computer Emergency Response Team) reports on vulnerabilities, there isn't a widely recognized 'CERT Top 10' that serves as a standardized list of all common security weaknesses and exploits in the same manner as CVE.

Concept tested: Common Vulnerabilities and Exposures (CVE)

Source: https://cve.mitre.org/

Topics

#Vulnerability Management#CVE#Security Standards#Weaknesses and Exploits

Community Discussion

No community discussion yet for this question.

Full SSCP Practice