Prioritizing Vulnerability Patching with CVSS

Answer Correct answer: B — The security director uses the Common Vulnerability Scoring System (CVSS) to assign severity scores that enable effective prioritization of vulnerability patching.

Which of the following can a security director use to prioritize vulnerability patching within a company's IT environment?

  1. SOAR
  2. CVSS Correct Answer
  3. SIEM
  4. CVE

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between identifying vulnerabilities (CVE) and scoring them for prioritization (CVSS), a common trap for candidates confusing identification with assessment.

The Common Vulnerability Scoring System (CVSS) provides a standardized severity score to help security directors prioritize patching efforts based on exploitability and impact.

Candidates often select CVE because it identifies specific flaws, but failing to recognize that CVEs lack the quantitative data needed for prioritization leads to incorrect choices.

Community Discussion (7 comments)

AspiringNerd 👍 1 Selected: B
Common Vulnerability Scoring System... used to prioritize common vulnerabilities within an Org.
Abdulaa 👍 2
23 APR 2024 I took my exam and passed this question on my exam this website was very helpful, study it and understood the answer. GL.
gab2024 👍 4 Selected: B
100% B. In my exam. this is under section 1.7 and I aced section 1.7 questions.
DrakeMallard 👍 1 Selected: B
Common Vulnerability Scoring System
salah112 👍 2 Selected: B
B. CVSS The Common Vulnerability Scoring System (CVSS) is a framework that provides a standardized method for assessing and prioritizing vulnerabilities. It assigns a score to each vulnerability based on various factors such as the impact, exploitability, and complexity of the attack. The CVSS score helps security professionals, including a security director, to prioritize which vulnerabilities should be addressed first.
Hs1208 👍 1 Selected: B
B. CVSS (Common Vulnerability Scoring System) The Common Vulnerability Scoring System (CVSS) is a framework used to assess and prioritize vulnerabilities based on their severity.
[Removed] 👍 1 Selected: B
The key word here is PRIORITIZE and if you know what systems are most vulnerable you can prioritized what to fix first. your not going to fix something that has a scan of one compared to something that has a score of 9.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CVSS is the industry-standard framework used to assess and prioritize vulnerabilities. By assigning a numerical score (0-10) based on factors like attack vector, complexity, and impact, it allows security directors to objectively rank which patches address the most critical risks first.

Why the Other Options Are Wrong

CVE is merely an identifier or label for a vulnerability, lacking any inherent severity data. SIEM is a logging and monitoring tool that aggregates events but does not inherently provide a prioritization framework for patching. SOAR automates response workflows but relies on inputs like CVSS scores to determine priority.

Community Comment Notes

Community consensus strongly supports B, with users noting that CVSS is the standard for 'prioritizing' vulnerabilities. As salah112 noted, it assigns scores based on impact and exploitability. Hs1208 emphasized that CVSS assesses severity to guide decisions.

Exam Strategy

Always look for keywords like 'prioritize', 'score', or 'severity' when evaluating vulnerability tools. If the question asks how to measure risk magnitude, choose CVSS; if it asks for identification, choose CVE.

Frequently Asked Questions

Why is CVE not the correct answer for prioritization?

CVE is just a unique identifier (like a name) for a vulnerability. It does not contain information about severity or impact, so you cannot prioritize based on it alone.

How does CVSS differ from SIEM in patching?

SIEM collects logs and alerts, while CVSS provides the actual severity score. A security director uses CVSS data to decide which alerts require immediate patching.

Related Analysis

← Back to SY0-601 Study Guide