The framework that provides vulnerability metrics and characteristics to support the National Vulnerability Database (NVD) is the Common Vulnerability Scoring System (CVSS).
CVSS is a standardized framework for assessing and rating the severity of vulnerabilities. It provides a set of metrics and scores that help to quantify the impact and exploitability of vulnerabilities. These scores are used by the NVD to provide consistent and objective information about vulnerabilities in various software and systems.
Therefore, option C, Common Vulnerability Scoring System (CVSS), is the correct answer.
C. "The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the
characteristics and impacts of IT vulnerabilities. The National Vulnerability Database (NVD) provides specific CVSS scores for publicly known vulnerabilities."
https://www.govinfo.gov/content/pkg/GOVPUB-C13-19c8184048f013016412405161920394/pdf/GOVPUB-C13-19c8184048f013016412405161920394.pdf
C-The Common Vulnerability Scoring System (aka CVSS Scores) provides a numerical (0-10) representation of the severity of an information security vulnerability. CVSS scores are commonly used by infosec teams as part of a vulnerability management program to provide a point of comparison between vulnerabilities, and to prioritize remediation of vulnerabilities.
A CVSS score is composed of three sets of metrics (Base, Temporal, Environmental), each of which have an underlying scoring component.
Given answer is correct:
!
The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities:
https://nvd.nist.gov/
CVE is a list of publicly disclosed cybersecurity vulnerabilities and exposures that is free to search, use, and incorporate into products and services. NVD, a U.S. government repository, is the CVE List augmented with additional analysis, a database, and a fine-grained search engine. The NVD is synchronized with CVE such that any updates to CVE appear immediately on the NVD.
https://nvd.nist.gov/general/FAQ-Sections/General-FAQs
C is Correct
The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. CVSS consists of three metric groups: Base, Temporal, and Environmental
https://nvd.nist.gov/vuln-metrics/cvss
Answer is correct
"A CVSS score is composed of three sets of metrics (Base, Temporal, Environmental), each of which have an underlying scoring component."
https://www.balbix.com/insights/understanding-cvss-scores/
The answer is "A" - based on the qeustion. CVSS is just a CVE scoring system.
upvoted 4 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Vino22
Highly Voted 2 years, 1 month agoJohnBentass
5 months, 2 weeks agoTheManiac
Most Recent 6 months, 1 week agoExamTaker1995
1 year, 1 month agoBach1968
1 year, 4 months agoHughJassole
1 year, 5 months agoNJALPHA
1 year, 7 months agojackdryan
1 year, 6 months agoinit2winit
1 year, 10 months agosomkiatr
1 year, 10 months agorajkamal0
1 year, 11 months agooudmaster
1 year, 11 months agosphenixfire
2 years agoJamati
2 years agoexplorer3
2 years, 1 month agoJamati
2 years agoToyeeb
2 years, 1 month agoJAckThePip
2 years, 1 month agofranbarpro
2 years, 1 month ago