Which of the following is best to use when determining the severity of a vulnerability?
Choose an answer
Tap an option to check your answer.
Correct answer: CVSS.
Why this is the answer
CVSS (Common Vulnerability Scoring System) is the best choice for determining the severity of a vulnerability because it provides a standardized, open framework for rating IT vulnerabilities. It assigns numerical scores that reflect the severity and helps prioritize remediation efforts. CVE (Common Vulnerabilities and Exposures) is a dictionary of publicly known cybersecurity vulnerabilities and exposures, but it doesn't provide a severity score. OSINT (Open-Source Intelligence) refers to data collected from publicly available sources and is not a vulnerability scoring system. SOAR (Security Orchestration, Automation, and Response) is a platform that helps organizations manage and automate security operations, but it doesn't inherently determine vulnerability severity.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed