Which two statements are true about CVSS? (Choose two.)
- CVSS is vendor agnostic.
- CVSS is Cisco proprietary.
- CVSS is designed to calculate the chances of a network being attacked.
- CVSS is designed to help organizations determine the urgency of responding to an attack.
Explanation & Hint:
The two true statements about CVSS (Common Vulnerability Scoring System) are:
CVSS is not designed to calculate the chances of a network being attacked, which is more in the realm of threat intelligence and risk assessment. Additionally, CVSS is not proprietary to Cisco or any other company; it is a free and open industry standard. |