Which of the following can best contribute to prioritizing patch applications?
Choose an answer
Tap an option to check your answer.
Correct answer: CVSS.
Why this is the answer
CVSS (Common Vulnerability Scoring System) provides a standardized, numerical score that reflects the severity of a vulnerability. This score helps organizations prioritize which vulnerabilities to patch first, focusing resources on those posing the highest risk. SCAP (Security Content Automation Protocol) is a suite of specifications for maintaining the security of enterprise systems, but it doesn't directly prioritize patching. OSINT (Open-Source Intelligence) is data collected from publicly available sources and is used for threat intelligence, not vulnerability prioritization. CVE (Common Vulnerabilities and Exposures) is a dictionary of publicly known cybersecurity vulnerabilities, providing a common identifier, but it doesn't assign a severity score for prioritization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed