Courseiva

CISSP Security Assessment and Testing Practice Question

Which vulnerability scoring system is commonly used to assess the severity of vulnerabilities?

⚠ Common exam trap

The CISSP exam often tests the distinction between a vulnerability database (NVD), a naming standard (CVE), and a scoring system (CVSS), so the trap here is confusing the repository or identifier with the actual scoring methodology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CVSS

The Common Vulnerability Scoring System (CVSS) is the industry-standard framework for assigning a numerical severity score (0–10) to a vulnerability based on metrics like attack vector, complexity, privileges required, and impact. It is maintained by the Forum of Incident Response and Security Teams (FIRST) and is widely adopted by organizations for prioritization in vulnerability management. CVSS provides a consistent, quantitative measure that allows security teams to compare and triage vulnerabilities across different systems and vendors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CVSS

    Why this is correct

    CVSS provides a standardised, vendor-neutral framework that scores vulnerabilities from 0.0 to 10.0 across base, temporal and environmental metrics, satisfying the stem's requirement for a commonly used severity assessment system. Its base metric group alone captures exploitability and impact, enabling consistent prioritisation across disparate platforms and tooling.

  • ✗

    NVD

    Why it's wrong here

    The NVD is a vulnerability database that republishes CVE records enriched with CVSS scores; it does not itself define the scoring system. It is tempting because severity ratings appear there, and it would be the right answer if the question asked where to look up scored vulnerabilities.

  • ✗

    CVE

    Why it's wrong here

    CVE is an identifier catalogue assigning unique reference numbers to disclosed vulnerabilities; it carries no severity metric or score. It is tempting because CVE entries are widely quoted alongside severity, and it would be correct if the question asked how vulnerabilities are uniquely named and tracked.

  • ✗

    OWASP

    Why it's wrong here

    OWASP is a community project producing guidance such as the Top Ten and testing tools; it publishes no general vulnerability scoring system. It is tempting because OWASP risk ratings appear in web application work, and it would be correct if the question concerned web application security categories or testing methodology.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.