Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 153 discussion

Actual exam question from ISC's CISSP
Question #: 153
Topic #: 1
[All CISSP Questions]

Which of the following frameworks provides vulnerability metrics and characteristics to support the National Vulnerability Database (NVD)?

  • A. Common Vulnerabilities and Exposures (CVE)
  • B. Center for Internet Security (CIS)
  • C. Common Vulnerability Scoring System (CVSS)
  • D. Open Web Application Security Project (OWASP)
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Vino22
Highly Voted 2 years, 1 month ago
A is correct https://cve.mitre.org/about/cve_and_nvd_relationship.html
upvoted 11 times
JohnBentass
5 months, 2 weeks ago
Question says metrics. Hence answer should be C
upvoted 1 times
...
...
TheManiac
Most Recent 6 months, 1 week ago
Selected Answer: C
CVSS is the correct answer. what about CVE? It gives you characteristics but not the metrics. Score on CVSS is the metric for example
upvoted 1 times
...
ExamTaker1995
1 year, 1 month ago
Selected Answer: C
CVSS is the framework for creating the metrics that determine CVEs. key word here is metrics
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: C
The framework that provides vulnerability metrics and characteristics to support the National Vulnerability Database (NVD) is the Common Vulnerability Scoring System (CVSS). CVSS is a standardized framework for assessing and rating the severity of vulnerabilities. It provides a set of metrics and scores that help to quantify the impact and exploitability of vulnerabilities. These scores are used by the NVD to provide consistent and objective information about vulnerabilities in various software and systems. Therefore, option C, Common Vulnerability Scoring System (CVSS), is the correct answer.
upvoted 2 times
...
HughJassole
1 year, 5 months ago
C. "The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. The National Vulnerability Database (NVD) provides specific CVSS scores for publicly known vulnerabilities." https://www.govinfo.gov/content/pkg/GOVPUB-C13-19c8184048f013016412405161920394/pdf/GOVPUB-C13-19c8184048f013016412405161920394.pdf
upvoted 1 times
...
NJALPHA
1 year, 7 months ago
C-The Common Vulnerability Scoring System (aka CVSS Scores) provides a numerical (0-10) representation of the severity of an information security vulnerability. CVSS scores are commonly used by infosec teams as part of a vulnerability management program to provide a point of comparison between vulnerabilities, and to prioritize remediation of vulnerabilities. A CVSS score is composed of three sets of metrics (Base, Temporal, Environmental), each of which have an underlying scoring component.
upvoted 1 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
init2winit
1 year, 10 months ago
Selected Answer: C
CVSS - Keyword here is Metrics
upvoted 2 times
...
somkiatr
1 year, 10 months ago
Selected Answer: C
Reference : https://www.balbix.com/insights/whats-the-difference-between-cve-and-cvss/
upvoted 1 times
...
rajkamal0
1 year, 11 months ago
Selected Answer: C
C is the best answer. https://ieeexplore.ieee.org/abstract/document/8594738
upvoted 1 times
...
oudmaster
1 year, 11 months ago
Selected Answer: C
Given answer is correct: ! The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities: https://nvd.nist.gov/
upvoted 1 times
...
sphenixfire
2 years ago
Selected Answer: C
Metrics and character = cvss https://nvd.nist.gov/vuln/vulnerability-detail-pages
upvoted 3 times
...
Jamati
2 years ago
Selected Answer: A
CVE is a list of publicly disclosed cybersecurity vulnerabilities and exposures that is free to search, use, and incorporate into products and services. NVD, a U.S. government repository, is the CVE List augmented with additional analysis, a database, and a fine-grained search engine. The NVD is synchronized with CVE such that any updates to CVE appear immediately on the NVD. https://nvd.nist.gov/general/FAQ-Sections/General-FAQs
upvoted 2 times
...
explorer3
2 years, 1 month ago
Selected Answer: C
C is Correct The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. CVSS consists of three metric groups: Base, Temporal, and Environmental https://nvd.nist.gov/vuln-metrics/cvss
upvoted 3 times
Jamati
2 years ago
CVSS is a scoring system, it does not provide the characteristics and attributes of the vulnerability.
upvoted 1 times
...
...
Toyeeb
2 years, 1 month ago
i agree with Vino, it is A
upvoted 2 times
...
JAckThePip
2 years, 1 month ago
Answer is correct "A CVSS score is composed of three sets of metrics (Base, Temporal, Environmental), each of which have an underlying scoring component." https://www.balbix.com/insights/understanding-cvss-scores/
upvoted 4 times
franbarpro
2 years, 1 month ago
The answer is "A" - based on the qeustion. CVSS is just a CVE scoring system.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...