Which of the following is used to quantitatively measure the criticality of a vulnerability?
Choose an answer
Tap an option to check your answer.
Correct answer: CVSS.
Why this is the answer
CVSS (Common Vulnerability Scoring System) is the correct answer because it provides a standardized, quantitative method for rating the severity and characteristics of software vulnerabilities. It uses a set of metrics to generate a numerical score reflecting the criticality of a vulnerability, allowing organizations to prioritize remediation efforts. CVE (Common Vulnerabilities and Exposures) is a dictionary of publicly known cybersecurity vulnerabilities and exposures, providing a common identifier for each, but it does not quantitatively measure criticality. CIA (Confidentiality, Integrity, Availability) is a security triad representing the fundamental goals of information security, not a vulnerability scoring system. CERT (Computer Emergency Response Team) is a group that handles computer security incidents, but it is not a system for quantitatively measuring vulnerability criticality.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed