セキュリティ ディレクターが企業の IT 環境内で脆弱性のパッチ適用を優先順位付けするために使用できるのは次のうちどれですか。
正解:B
The Common Vulnerability Scoring System (CVSS) is a standardized framework for assessing the severity of security vulnerabilities. It helps organizations prioritize vulnerability patching by providing a numerical score that reflects the potential impact and exploitability of a vulnerability. CVSS scores are used to gauge the urgency of patching vulnerabilities within a company's IT environment. Reference = CompTIA Security+ SY0-701 Course Content: Domain 05 Security Program Management and Oversight. CompTIA Security+ SY0-601 Study Guide: Chapter on Vulnerability Management.