脆弱性評価エンドポイントは、最新の調査結果のレポートを生成しました。セキュリティ アナリストはレポートを確認し、対処する必要がある項目の優先リストを作成する必要があります。リストをすばやく作成するためにアナリストが使用する必要があるのは、次のうちどれですか?
正解:C
CVSS scores (Common Vulnerability Scoring System) should be used to create a priority list of items that must be addressed. The CVSS is a standardized scoring system that is used to assess the severity of vulnerabilities based on a number of factors, including the impact on confidentiality, integrity, and availability, as well as the ease of exploit and the likelihood of an attack. Vulnerabilities are assigned a score on a scale of 0.0 to 10.0, with higher scores indicating a greater level of severity. By reviewing the CVSS scores of the vulnerabilities identified in the report, the security analyst can quickly determine which ones are the most critical and should be addressed first. Other factors, such as the business impact rating and the potential impact on the organization's operations, may also be taken into account when prioritizing patches.