Study. uk . com
  1. Home
  2. All questions
  3. Question 188

CISM study material · question 188 of 1000

The same technical vulnerability is rated critical on one system and low on another. Why is this consistent with SP 800-30?

  1. Severity depends on how recently the vulnerability was published, since newer weaknesses attract more attacker attention
  2. Severity is assigned by the scanner and varies with the product version installed on each of the two systems
  3. Severity reflects the harm that would follow from exploitation, which makes it context-dependent
  4. One of the two ratings must be an error
Show the answer

Answer: C. Severity reflects the harm that would follow from exploitation, which makes it context-dependent

SP 800-30 grades severity by how badly exploitation would hurt, which is a judgement about how urgent mitigation is here. The same flaw therefore rates differently on differently placed systems.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Vulnerabilities

Challenge yourself on this topic → Study as cards