Which database is the U.S. government repository that provides CVE details and vulnerability scores?

Prepare for the Certified Ethical Hacker Version 11 Exam with a comprehensive test featuring flashcards and multiple choice questions, each accompanied by hints and explanations to ensure a thorough understanding. Ace your ethical hacking exam with confidence!

Multiple Choice

Which database is the U.S. government repository that provides CVE details and vulnerability scores?

Explanation:
The National Vulnerability Database is the U.S. government repository for CVE details and vulnerability scores. It hosts CVE entries—the identifiers and descriptions assigned by MITRE—and augments them with CVSS-based severity scores, impact metrics, and related metadata. This combination makes it the authoritative source for both the vulnerability descriptions and their standardized risk ratings in a government-supported, publicly accessible database. The CVE itself is just the naming system for vulnerabilities, not a scoring database. OSVDB was a separate project that is no longer maintained, and CWE classifies software weaknesses rather than individual vulnerabilities or scores.

The National Vulnerability Database is the U.S. government repository for CVE details and vulnerability scores. It hosts CVE entries—the identifiers and descriptions assigned by MITRE—and augments them with CVSS-based severity scores, impact metrics, and related metadata. This combination makes it the authoritative source for both the vulnerability descriptions and their standardized risk ratings in a government-supported, publicly accessible database. The CVE itself is just the naming system for vulnerabilities, not a scoring database. OSVDB was a separate project that is no longer maintained, and CWE classifies software weaknesses rather than individual vulnerabilities or scores.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy