A published advisory assigns an identifier to a known flaw in the firmware version running on the city's VPN concentrators. How should the security team track that flaw?
Select an answer to reveal the explanation.
Short Explanation
CVE IDs are the shared license-plate numbers for known bugs. When the VPN box has a published flaw, tag work and scans with that CVE so everyone is fixing the same thing—not a homemade nickname.
Full Explanation
Common Vulnerabilities and Exposures (CVE) identifiers uniquely label publicly known vulnerabilities. Tracking city assets against CVE IDs enables consistent correlation across scanners, patch advisories, and remediation tickets. Ignoring public identifiers or inventing unrelated labels breaks that correlation and slows coordinated response.