ISC Certified Information Systems Security Professional (CISSP) CISSP Question # 228 Topic 23 Discussion

ISC Certified Information Systems Security Professional (CISSP) CISSP Question # 228 Topic 23 Discussion

CISSP Exam Topic 23 Question 228 Discussion:
Question #: 228
Topic #: 23

Which component of the Security Content Automation Protocol (SCAP) specification contains the data required to estimate the severity of vulnerabilities identified automated vulnerability assessments?


A.

Common Vulnerabilities and Exposures (CVE)


B.

Common Vulnerability Scoring System (CVSS)


C.

Asset Reporting Format (ARF)


D.

Open Vulnerability and Assessment Language (OVAL)


Get Premium CISSP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.