Which of the following should an organization focus on the most when making decisions about vulnerability prioritization?
Choose an answer
Tap an option to check your answer.
Correct answer: CVSS.
Why this is the answer
The Common Vulnerability Scoring System (CVSS) provides a standardized, open, and universally recognized method for rating IT vulnerabilities. It assigns numerical scores to vulnerabilities based on their characteristics, such as exploitability, impact, and privileges required. This allows organizations to objectively prioritize which vulnerabilities to address first, focusing on those with the highest scores, which represent the greatest risk. Exposure factor is a component of risk assessment, representing the percentage of asset value lost due to a threat, but it doesn't directly prioritize vulnerabilities. CVE (Common Vulnerabilities and Exposures) provides a dictionary of publicly known cybersecurity vulnerabilities, but it doesn't include a scoring system for prioritization. Industry impact is a qualitative factor that might influence prioritization but lacks the objective, standardized scoring of CVSS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed