A security analyst is investigating a newly reported software vulnerability and needs to review its official description, standardized Common Vulnerability Scoring System (CVSS) metrics, and vendor patch links. Which threat intelligence source is specifically designed to provide this centralized repository of public vulnerability data?
- National Vulnerability Database (NVD)Cevap
- BInformation Sharing and Analysis Center (ISAC)
- CDark web threat forum
- DNetwork firewall access control list (ACL)
Cevap
National Vulnerability Database (NVD)
The National Vulnerability Database (NVD) is a public repository maintained by NIST that integrates with the CVE dictionary to offer standardized vulnerability details, CVSS severity scores, and remediation links.
Adım Adım Çözüm
Anahtar Kavram
Public Vulnerability Databases (NVD/CVE)