exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 354 discussion

Actual exam question from CompTIA's SY0-601
Question #: 354
Topic #: 1
[All SY0-601 Questions]

A security analyst is looking for a solution to help communicate to the leadership team the severity levels of the organization’s vulnerabilities. Which of the following would BEST meet this need?

  • A. CVE
  • B. SIEM
  • C. SOAR
  • D. CVSS
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Adji91
Highly Voted 2 years, 3 months ago
Just passed my exam today 22 March 2023 with 799 score. This platform has helped. This question was on the test. Right answer D.
upvoted 30 times
P_man
2 years, 3 months ago
Congratulations! I'm testing tomorrow
upvoted 5 times
bitezadusto
2 years, 3 months ago
did ya pass?
upvoted 1 times
...
...
fouserd
2 years, 2 months ago
Congrats mate i am hoping to pass on the 9th of May
upvoted 2 times
...
...
ApplebeesWaiter1122
Highly Voted 1 year, 11 months ago
*On Exam, Taken On July 31, 2023*
upvoted 13 times
ThaKyd88
1 year, 7 months ago
I hope you did well
upvoted 1 times
...
...
zits88
Most Recent 1 year, 10 months ago
Selected Answer: D
Leadership teams like more "snapshot" explanations than long technical explanations. The Common Vulnerability Scoring System (CVSS) provides an externally validated and informative "snapshot" of what an organization is up against, rather than just a grunt IT worker's "opinion" (however valid it may be) that something is a big deal. Also, in my experience the CVSS's are usually shown in colors. Colors help with C-suite personnel. (Speaking from experience.)
upvoted 6 times
...
Selected Answer: D
CVSS is a widely recognized and standardized framework for assessing and communicating the severity of vulnerabilities. It provides a numeric score and severity rating for vulnerabilities based on various factors such as impact, exploitability, and complexity. The CVSS score helps to prioritize vulnerabilities and determine the appropriate response and mitigation actions. By utilizing CVSS, the security analyst can provide a clear and standardized way to communicate the severity levels of vulnerabilities to the leadership team. The CVSS score and rating provide a common language to convey the potential risks and impact associated with each vulnerability, allowing the leadership team to make informed decisions regarding the organization's security posture and resource allocation.
upvoted 3 times
...
SophyQueenCR82
2 years, 3 months ago
The Common Vulnerability Scoring System is a free and open industry standard for assessing the severity of computer system security vulnerabilities. CVSS attempts to assign severity scores to vulnerabilities, allowing responders to prioritize responses and resources according to threat.
upvoted 2 times
...
Ufuk_Ari
2 years, 4 months ago
Selected Answer: D
Could use a Common Vulnerability Scoring System (CVSS) to communicate the severity levels of the organization's vulnerabilities to the leadership team.
upvoted 5 times
...
hsdj
2 years, 4 months ago
Selected Answer: D
Differences between CVSS and CVE CVSS is the overall score assigned to a vulnerability. CVE is simply a list of all publicly disclosed vulnerabilities that includes the CVE ID, a description, dates, and comments. The CVSS score is not reported in the CVE listing
upvoted 7 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...