Prioritizing Vulnerability Patching with CVSS
Which of the following can a security director use to prioritize vulnerability patching within a company's IT environment?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between identifying vulnerabilities (CVE) and scoring them for prioritization (CVSS), a common trap for candidates confusing identification with assessment.
The Common Vulnerability Scoring System (CVSS) provides a standardized severity score to help security directors prioritize patching efforts based on exploitability and impact.
Candidates often select CVE because it identifies specific flaws, but failing to recognize that CVEs lack the quantitative data needed for prioritization leads to incorrect choices.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
CVSS is the industry-standard framework used to assess and prioritize vulnerabilities. By assigning a numerical score (0-10) based on factors like attack vector, complexity, and impact, it allows security directors to objectively rank which patches address the most critical risks first.Why the Other Options Are Wrong
CVE is merely an identifier or label for a vulnerability, lacking any inherent severity data. SIEM is a logging and monitoring tool that aggregates events but does not inherently provide a prioritization framework for patching. SOAR automates response workflows but relies on inputs like CVSS scores to determine priority.Community Comment Notes
Community consensus strongly supports B, with users noting that CVSS is the standard for 'prioritizing' vulnerabilities. As salah112 noted, it assigns scores based on impact and exploitability. Hs1208 emphasized that CVSS assesses severity to guide decisions.Exam Strategy
Always look for keywords like 'prioritize', 'score', or 'severity' when evaluating vulnerability tools. If the question asks how to measure risk magnitude, choose CVSS; if it asks for identification, choose CVE.
Frequently Asked Questions
Why is CVE not the correct answer for prioritization?
CVE is just a unique identifier (like a name) for a vulnerability. It does not contain information about severity or impact, so you cannot prioritize based on it alone.
How does CVSS differ from SIEM in patching?
SIEM collects logs and alerts, while CVSS provides the actual severity score. A security director uses CVSS data to decide which alerts require immediate patching.