Study. uk . com
  1. Home
  2. All questions
  3. Question 57

CISSP study material · question 57 of 500

A vulnerability scan of a hospital's intranet returns findings ranked by the scanning product's own severity labels. Management proposes to publish that ranked list as the organisation's statement of risk. Which two objections should the assessment lead raise? Choose two.

  1. Severity labels vary between products and need not correspond to the business risk of the affected system
  2. Scanners report potential rather than confirmed exposure, so exploitation during testing is what settles aggregate risk
  3. Scanners chain individually trivial findings into attack paths, so the ranked list overstates the real exposure
  4. Severity labels follow one industry-wide scale, so the ranking is sound once the affected asset names are redacted
Show the answer

Answer: A. Severity labels vary between products and need not correspond to the business risk of the affected system
B. Scanners report potential rather than confirmed exposure, so exploitation during testing is what settles aggregate risk

Scanner severity is vendor-defined rather than business risk, and findings signal possible exposure. Scanners miss combinations of separately trivial flaws instead of chaining them.

Source: NIST SP 800-115 (NIST) — SP 800-115 > Section 4.3, Vulnerability Scanning

Challenge yourself on this topic → Study as cards