Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 396 discussion

Actual exam question from ISC's CISSP
Question #: 396
Topic #: 1
[All CISSP Questions]

A Chief Information Security Officer (CISO) is considering various proposals for evaluating security weaknesses and vulnerabilities at the source code level. Which of the following items BEST equips the CISO to make smart decisions for the organization?

  • A. The Common Weakness Risk Analysis Framework (CWRAF)
  • B. The Common Vulnerabilities and Exposures (CVE)
  • C. The Common Weakness Enumeration (CWE)
  • D. The Open Web Application Security Project (OWASP) Top Ten
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
l00t
Highly Voted 1 year, 9 months ago
Selected Answer: A
The best item to equip the CISO to make smart decisions for the organization is A. The Common Weakness Risk Analysis Framework (CWRAF). CWRAF is a framework that helps prioritize the security weaknesses and vulnerabilities in source code based on the operational context and potential impact of the software. CWRAF can also correlate scan findings to Common Weakness Enumeration (CWE) and Security Technical Implementation Guides (STIGs) to provide a comprehensive report of the security risks. The other items, such as CVE, CWE, and OWASP Top Ten, are useful sources of information about common vulnerabilities and exposures, but they do not provide a tailored analysis of the source code based on the specific operational environment and requirements.
upvoted 9 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
iwannapass
1 year, 9 months ago
Where did you get the evidence for this answer? I'm glad you know this, I'd like to find a reading source to learn more about this
upvoted 2 times
l00t
1 year, 9 months ago
Use (the new) Bing.com as your search engine. ;-) From there, you can dig deeper into the specific topics.
upvoted 4 times
...
...
...
deeden
Most Recent 3 months, 1 week ago
Selected Answer: C
A. CWRAF is a framework that provides a method for prioritizing software weaknesses based on specific contexts, such as particular business domains or technologies. While useful, it is not as directly focused on identifying and understanding source code weaknesses as CWE. C. CWE is a comprehensive list of software weaknesses and vulnerabilities at the source code level. It provides detailed information about the common types of flaws that can occur in software development, making it an essential tool for evaluating and understanding security weaknesses in code. Example: If you’re developing a web application and run a static analysis tool that identifies a potential SQL injection vulnerability, the tool might map this issue to CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').
upvoted 2 times
...
1460168
3 months, 3 weeks ago
Selected Answer: C
I go with C: About CWE Common Weakness Enumeration (CWE™) is a community-developed list of common software and hardware weaknesses. A “weakness” is a condition in a software, firmware, hardware, or service component that, under certain circumstances, could contribute to the introduction of vulnerabilities. The CWE List and associated classification taxonomy identify and describe weaknesses in terms of CWEs. Knowing the weaknesses that result in vulnerabilities means software developers, hardware designers, and security architects can eliminate them before deployment, when it is much easier and cheaper to do so. Source: https://cwe.mitre.org/about/index.html
upvoted 3 times
...
GuardianAngel
9 months, 2 weeks ago
I think the answer is C: The common weakness Enumeration CWRAF focuses on risk analysis and mitigation, providing a framework to prioritize and address vulnerabilities in software development and implementation processes. CVE, on the other hand, is a dictionary of publicly known vulnerabilities and exposures but does not provide the same level of granularity and detailed information as CWE when it comes to source code weaknesses. WE helps developers and security practitioners to: Describe and discuss software and hardware weaknesses in a common language. Check for weaknesses in existing software and hardware products. Evaluate coverage of tools targeting these weaknesses. Leverage a common baseline standard for weakness identification, mitigation, and prevention efforts. Prevent software and hardware vulnerabilities prior to deployment. https://cwe.mitre.org/about/
upvoted 2 times
...
Soleandheel
11 months, 1 week ago
A. The Common Weakness Risk Analysis Framework (CWRAF) CWRAF is specifically designed to assess and prioritize common software weaknesses and vulnerabilities based on their risk. It helps organizations focus on addressing the most critical issues first, taking into account the potential impact and likelihood of exploitation. This is particularly valuable when evaluating security weaknesses at the source code level, as it allows the CISO to make informed decisions about which vulnerabilities should be addressed first to reduce the organization's overall risk.
upvoted 2 times
...
Delab202
1 year, 7 months ago
Selected Answer: A
The Common Weakness Risk Analysis Framework (CWRAF) is a risk assessment methodology that is used to identify, assess, and prioritize software weaknesses (also known as vulnerabilities) based on the potential impact on an organization's assets and operations.
upvoted 1 times
...
MarkSun
1 year, 7 months ago
Selected Answer: A
The Common Weakness Risk Analysis Framework (CWRAF) is a method for identifying and prioritizing security vulnerabilities in software systems. It is a systematic approach that considers the potential impact and likelihood of an attack on a specific weakness. CWRAF is based on the Common Weakness Enumeration (CWE) database, which provides a standardized list of known security weaknesses in software. The framework provides a structured way to assess the risk associated with each weakness and prioritize them based on their potential impact.
upvoted 1 times
...
zak786
1 year, 8 months ago
C looks correct - CWE stands for Common Weakness Enumeration. It is a community-developed list of common software security weaknesses that is maintained by the MITRE Corporation. CWE provides a common language for describing software security weaknesses in architecture, design, or code. Each CWE entry includes a description of the weakness, its potential consequences, and ways to detect and mitigate it. CWE is widely used in software development, testing, and security communities to identify and prioritize software vulnerabilities.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...