Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC GCCC Exam - Topic 5 Question 81 Discussion

Which option best assigns a number indicating the severity of a discovered software vulnerability?
D) CVSS
B) CVE
A) CPE
C) CCE

GIAC GCCC Exam - Topic 5 Question 81 Discussion

Actual exam question for GIAC's GCCC exam
Question #: 81
Topic #: 5
[All GCCC Questions]

Which option best assigns a number indicating the severity of a discovered software vulnerability?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Jeff
1 month ago
True, but it gives a clear picture of risk levels.
upvoted 0 times
...
Jody
2 months ago
But it can be complex to understand for beginners.
upvoted 0 times
...
Veronica
2 months ago
Agreed! It’s standardized and widely accepted.
upvoted 0 times
...
Viva
2 months ago
I think the CVSS score is the best way to rate severity.
upvoted 0 times
...
Fabiola
4 months ago
I heard some vulnerabilities get rated too high sometimes.
upvoted 0 times
...
Alpha
4 months ago
Wait, are we sure CVSS is always accurate?
upvoted 0 times
...
Kathrine
4 months ago
I think some companies use their own systems though.
upvoted 0 times
...
Merri
4 months ago
Totally agree, CVSS is the way to go!
upvoted 0 times
...
Ernest
4 months ago
CVSS scores are the standard for this.
upvoted 0 times
...
Tennie
4 months ago
Haha, the real severity is how many all-nighters the dev team has to pull to patch this thing.
upvoted 0 times
...
Emeline
5 months ago
Option D is the way to go. Detailed and objective - just how I like my vulnerability assessments.
upvoted 0 times
...
Alise
5 months ago
I'd go with Option B. Gotta keep it simple, right?
upvoted 0 times
...
Gracie
5 months ago
Option C seems the most comprehensive, covering all the key factors to consider.
upvoted 0 times
...
Glory
5 months ago
The severity of a software vulnerability should be measured in how many coffee breaks it takes to fix it.
upvoted 0 times
...
Jackie
5 months ago
I feel like the answer might involve some kind of numerical scale, but I can't remember the exact details we covered.
upvoted 0 times
...
Shayne
5 months ago
Wasn't there something about low, medium, and high severity levels? I hope I can recall the specific numbers during the exam.
upvoted 0 times
...
Hildegarde
6 months ago
I remember a practice question that asked about vulnerability ratings, and I think it was related to risk assessment.
upvoted 0 times
...
Virgie
6 months ago
I think we talked about the CVSS scoring system in class, but I'm not entirely sure how to apply it to this question.
upvoted 0 times
...
Audria
7 months ago
I've got a good handle on vulnerability assessment, so I think I'd be able to work through this step-by-step to determine the most appropriate severity rating.
upvoted 0 times
...
Annamae
7 months ago
I'm a bit unsure about this one. Maybe I'd try to brainstorm a list of criteria to consider and then see if any common vulnerability scoring models fit the bill.
upvoted 0 times
...
Doug
7 months ago
Okay, for this type of question, I'd try to apply a standardized vulnerability scoring system like CVSS to systematically evaluate the different risk factors.
upvoted 0 times
...
Halina
7 months ago
Hmm, this seems like a tricky one. I'd need to review my notes on vulnerability assessment frameworks to figure out the best approach.
upvoted 0 times
...
Callie
7 months ago
I think I'd start by considering the different factors that could contribute to the severity of a software vulnerability, like the potential impact, ease of exploitation, and availability of a fix.
upvoted 0 times
Jillian
29 days ago
And what about the fix availability? That’s key!
upvoted 0 times
...
Barney
1 month ago
Definitely! Exploitability matters too.
upvoted 0 times
...
Dallas
1 month ago
I agree, impact is crucial.
upvoted 0 times
...
...

Save Cancel