Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium

A security team is implementing a vulnerability management program and needs to establish a systematic approach to identify and categorize vulnerabilities. They decide to use a publicly available, standardized system for naming and identifying vulnerabilities. Which system are they most likely to adopt?

  1. ACVSS (Common Vulnerability Scoring System)
  2. BNIST SP 800-53
  3. COWASP Top 10
  4. DCVE (Common Vulnerabilities and Exposures)
Show answer & explanation

Correct answer: D. CVE (Common Vulnerabilities and Exposures)

CVE (Common Vulnerabilities and Exposures) provides a standard naming system for publicly known cybersecurity vulnerabilities. It assigns a unique identifier (e.g., CVE-2023-XXXX) to each vulnerability, allowing security teams to consistently track and reference specific flaws across different tools and reports.

Why the other options are wrong

  • A. CVSS is a system for scoring the severity of vulnerabilities, not for naming or identifying them.
  • B. NIST SP 800-53 is a catalog of security controls for federal information systems, not a vulnerability identification system.
  • C. OWASP Top 10 lists the most critical web application security risks, not a system for naming individual vulnerabilities.

CVE (Common Vulnerabilities and Exposures)

A list of publicly disclosed cybersecurity vulnerabilities, each assigned a unique identifier (CVE ID) to facilitate data sharing and enable automation.

  • Standardizes vulnerability identification.
  • Maintained by MITRE Corporation.
  • Used by security vendors and researchers worldwide.

Memory trick: CVE IDs give vulnerabilities a name.

More Vulnerability Management questions