ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 131 - CV0-004 discussion

Report
Export

An organization has been using an old version of an Apache Log4j software component in its critical software application. Which of the following should the organization use to calculate the severity of the risk from using this component?

A.
CWE
Answers
A.
CWE
B.
CVSS
Answers
B.
CVSS
C.
CWSS
Answers
C.
CWSS
D.
CVE
Answers
D.
CVE
Suggested answer: B

Explanation:

The Common Vulnerability Scoring System (CVSS) is what the organization should use to calculate the severity of the risk from using an old version of Apache Log4j software component. CVSS provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.

Reference: CompTIA Cloud+ Study Guide (Exam CV0-004) - Chapter on Risk Management

asked 02/10/2024
EduBP srl EduBP
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first