CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 153


Which of the following frameworks provides vulnerability metrics and characteristics to support the National Vulnerability Database (NVD)?

Show Answer
Correct Answer: C

The Common Vulnerability Scoring System (CVSS) is the framework that provides vulnerability metrics and characteristics to support the National Vulnerability Database (NVD). CVSS offers a standardized method to gauge the severity and characteristics of cyber vulnerabilities through a numerical scoring system, which is utilized by the NVD to supply consistent and objective vulnerability information.

Discussion

15 comments
Sign in to comment
Vino22Option: A
Oct 2, 2022

A is correct https://cve.mitre.org/about/cve_and_nvd_relationship.html

JohnBentass
Jun 8, 2024

Question says metrics. Hence answer should be C

JAckThePipOption: C
Oct 4, 2022

Answer is correct "A CVSS score is composed of three sets of metrics (Base, Temporal, Environmental), each of which have an underlying scoring component." https://www.balbix.com/insights/understanding-cvss-scores/

franbarpro
Oct 21, 2022

The answer is "A" - based on the qeustion. CVSS is just a CVE scoring system.

explorer3Option: C
Oct 24, 2022

C is Correct The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. CVSS consists of three metric groups: Base, Temporal, and Environmental https://nvd.nist.gov/vuln-metrics/cvss

Jamati
Nov 13, 2022

CVSS is a scoring system, it does not provide the characteristics and attributes of the vulnerability.

sphenixfireOption: C
Nov 12, 2022

Metrics and character = cvss https://nvd.nist.gov/vuln/vulnerability-detail-pages

ToyeebOption: A
Oct 20, 2022

i agree with Vino, it is A

JamatiOption: A
Nov 9, 2022

CVE is a list of publicly disclosed cybersecurity vulnerabilities and exposures that is free to search, use, and incorporate into products and services. NVD, a U.S. government repository, is the CVE List augmented with additional analysis, a database, and a fine-grained search engine. The NVD is synchronized with CVE such that any updates to CVE appear immediately on the NVD. https://nvd.nist.gov/general/FAQ-Sections/General-FAQs

init2winitOption: C
Jan 14, 2023

CVSS - Keyword here is Metrics

Bach1968Option: C
Jul 6, 2023

The framework that provides vulnerability metrics and characteristics to support the National Vulnerability Database (NVD) is the Common Vulnerability Scoring System (CVSS). CVSS is a standardized framework for assessing and rating the severity of vulnerabilities. It provides a set of metrics and scores that help to quantify the impact and exploitability of vulnerabilities. These scores are used by the NVD to provide consistent and objective information about vulnerabilities in various software and systems. Therefore, option C, Common Vulnerability Scoring System (CVSS), is the correct answer.

oudmasterOption: C
Dec 24, 2022

Given answer is correct: ! The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities: https://nvd.nist.gov/

rajkamal0Option: C
Dec 27, 2022

C is the best answer. https://ieeexplore.ieee.org/abstract/document/8594738

somkiatrOption: C
Jan 2, 2023

Reference : https://www.balbix.com/insights/whats-the-difference-between-cve-and-cvss/

NJALPHAOption: C
Apr 5, 2023

C-The Common Vulnerability Scoring System (aka CVSS Scores) provides a numerical (0-10) representation of the severity of an information security vulnerability. CVSS scores are commonly used by infosec teams as part of a vulnerability management program to provide a point of comparison between vulnerabilities, and to prioritize remediation of vulnerabilities. A CVSS score is composed of three sets of metrics (Base, Temporal, Environmental), each of which have an underlying scoring component.

jackdryan
May 13, 2023

C is correct

HughJassoleOption: C
Jun 25, 2023

C. "The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. The National Vulnerability Database (NVD) provides specific CVSS scores for publicly known vulnerabilities." https://www.govinfo.gov/content/pkg/GOVPUB-C13-19c8184048f013016412405161920394/pdf/GOVPUB-C13-19c8184048f013016412405161920394.pdf

ExamTaker1995Option: C
Oct 17, 2023

CVSS is the framework for creating the metrics that determine CVEs. key word here is metrics

TheManiacOption: C
May 18, 2024

CVSS is the correct answer. what about CVE? It gives you characteristics but not the metrics. Score on CVSS is the metric for example