List of questions
Related questions
Question 254 - CAS-004 discussion
Due to budget constraints, an organization created a policy that only permits vulnerabilities rated high and critical according to CVSS to be fixed or mitigated. A security analyst notices that many vulnerabilities that were previously scored as medium are now breaching higher thresholds. Upon further investigation, the analyst notices certain ratings are not aligned with the approved system categorization. Which of the following can the analyst do to get a better picture of the risk while adhering to the organization's policy?
A.
Align the exploitability metrics to the predetermined system categorization.
B.
Align the remediation levels to the predetermined system categorization.
C.
Align the impact subscore requirements to the predetermined system categorization.
D.
Align the attack vectors to the predetermined system categorization.
Your answer:
0 comments
Sorted by
Leave a comment first