Determining Vulnerability Severity with CVSS
Which of the following is best to use when determining the severity of a vulnerability?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the difference between identifying a vulnerability (CVE) and measuring its impact/severity (CVSS). The common trap is confusing the identifier with the scoring system.
CVSS is the standard framework used to quantify and communicate the severity of software vulnerabilities. This page explains why CVSS is superior to CVE for severity assessment in security operations.
Choosing CVE because it is the most famous vulnerability term, failing to realize CVE only provides identification while CVSS provides the actual severity score.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
CVSS (Common Vulnerability Scoring System) is specifically designed to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity. This score allows organizations to prioritize remediation efforts effectively based on the potential impact.Why the Other Options Are Wrong
CVE (Common Vulnerabilities and Exposures) is an identifier system that assigns unique names to vulnerabilities but does not provide any information regarding their severity or exploitability. OSINT (Open Source Intelligence) is a methodology for gathering information, not a specific tool for scoring. SOAR (Security Orchestration, Automation, and Response) is a platform for managing incident response workflows, not for initial vulnerability assessment.Community Comment Notes
Community feedback overwhelmingly supports CVSS as the correct answer. Users noted that CVSS provides a standardized numerical score to help prioritize vulnerabilities, confirming its role in determining severity rather than just identification.Exam Strategy
When asked about 'severity' or 'scoring' of vulnerabilities, always look for CVSS. If asked about 'identification' or 'naming', look for CVE. Memorize the distinction between the ID system and the scoring system.
Frequently Asked Questions
What is the difference between CVE and CVSS?
CVE is an identifier (like a name) for a vulnerability, while CVSS is a scoring system that measures its severity.
Can SOAR be used to assess vulnerability severity?
No, SOAR automates response workflows but does not calculate the inherent severity score of a vulnerability itself.