Continue your lesson
Connect each term to the asset, threat, control, and evidence it affects.
Block 1 of 1Compare CVE identifier · CVSS score · False positive · Compensating control
Current · 15 min
Compare CVE identifier · CVSS score · False positive · Compensating control
Optional concept notes
CVE identifier
Provides a common identifier for a publicly disclosed vulnerability.
CVSS score
Expresses standardized vulnerability severity rather than business-specific risk.
False positive
Reports a weakness that investigation shows is not present.
Compensating control
Reduces risk when the preferred remediation cannot yet be applied.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional organization. Name the risk, choose the narrowest useful control, and state what evidence would prove the control worked.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 4.3 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.