CISSP Security Assessment and Testing Practice Question
Which vulnerability scoring system is commonly used to assess the severity of vulnerabilities?
⚠ Common exam trap
The CISSP exam often tests the distinction between a vulnerability database (NVD), a naming standard (CVE), and a scoring system (CVSS), so the trap here is confusing the repository or identifier with the actual scoring methodology.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CVSS
The Common Vulnerability Scoring System (CVSS) is the industry-standard framework for assigning a numerical severity score (0–10) to a vulnerability based on metrics like attack vector, complexity, privileges required, and impact. It is maintained by the Forum of Incident Response and Security Teams (FIRST) and is widely adopted by organizations for prioritization in vulnerability management. CVSS provides a consistent, quantitative measure that allows security teams to compare and triage vulnerabilities across different systems and vendors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CVSS
Why this is correct
CVSS provides a standardised, vendor-neutral framework that scores vulnerabilities from 0.0 to 10.0 across base, temporal and environmental metrics, satisfying the stem's requirement for a commonly used severity assessment system. Its base metric group alone captures exploitability and impact, enabling consistent prioritisation across disparate platforms and tooling.
- ✗
NVD
Why it's wrong here
The NVD is a vulnerability database that republishes CVE records enriched with CVSS scores; it does not itself define the scoring system. It is tempting because severity ratings appear there, and it would be the right answer if the question asked where to look up scored vulnerabilities.
- ✗
CVE
Why it's wrong here
CVE is an identifier catalogue assigning unique reference numbers to disclosed vulnerabilities; it carries no severity metric or score. It is tempting because CVE entries are widely quoted alongside severity, and it would be correct if the question asked how vulnerabilities are uniquely named and tracked.
- ✗
OWASP
Why it's wrong here
OWASP is a community project producing guidance such as the Top Ten and testing tools; it publishes no general vulnerability scoring system. It is tempting because OWASP risk ratings appear in web application work, and it would be correct if the question concerned web application security categories or testing methodology.
Go deeper
Related to this question
Learn chapter
Incident Response and Business Continuity
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.