Determining Vulnerability Severity with CVSS

Answer Correct answer: D — Use CVSS to determine the severity of a vulnerability.

Which of the following is best to use when determining the severity of a vulnerability?

  1. CVE
  2. OSINT
  3. SOAR
  4. CVSS Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the difference between identifying a vulnerability (CVE) and measuring its impact/severity (CVSS). The common trap is confusing the identifier with the scoring system.

CVSS is the standard framework used to quantify and communicate the severity of software vulnerabilities. This page explains why CVSS is superior to CVE for severity assessment in security operations.

Choosing CVE because it is the most famous vulnerability term, failing to realize CVE only provides identification while CVSS provides the actual severity score.

Community Discussion (5 comments)

Abdulaa 👍 6
23 APR 2024 I took my exam and passed this question was on my exam this website was very helpful, study it and understood the answer. GL.
salah112 👍 2 Selected: D
D. CVSS The Common Vulnerability Scoring System (CVSS) is best to use when determining the severity of a vulnerability. CVSS is a standardized framework for assessing and communicating the characteristics and impact of security vulnerabilities. It provides a numerical score to help prioritize and compare vulnerabilities based on their severity.
Benrosan 👍 2 Selected: D
CVSS rates severity on a scale from 1-10.
RedDog2 👍 2 Selected: D
The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities.
Hs1208 👍 2 Selected: D
D. CVSS CVSS is a standardized framework for assessing and scoring the severity of security vulnerabilities.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CVSS (Common Vulnerability Scoring System) is specifically designed to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity. This score allows organizations to prioritize remediation efforts effectively based on the potential impact.

Why the Other Options Are Wrong

CVE (Common Vulnerabilities and Exposures) is an identifier system that assigns unique names to vulnerabilities but does not provide any information regarding their severity or exploitability. OSINT (Open Source Intelligence) is a methodology for gathering information, not a specific tool for scoring. SOAR (Security Orchestration, Automation, and Response) is a platform for managing incident response workflows, not for initial vulnerability assessment.

Community Comment Notes

Community feedback overwhelmingly supports CVSS as the correct answer. Users noted that CVSS provides a standardized numerical score to help prioritize vulnerabilities, confirming its role in determining severity rather than just identification.

Exam Strategy

When asked about 'severity' or 'scoring' of vulnerabilities, always look for CVSS. If asked about 'identification' or 'naming', look for CVE. Memorize the distinction between the ID system and the scoring system.

Frequently Asked Questions

What is the difference between CVE and CVSS?

CVE is an identifier (like a name) for a vulnerability, while CVSS is a scoring system that measures its severity.

Can SOAR be used to assess vulnerability severity?

No, SOAR automates response workflows but does not calculate the inherent severity score of a vulnerability itself.

Related Analysis

← Back to SY0-601 Study Guide