What is the primary purpose of trend reporting on vulnerability risk scores over successive reporting periods?
- ATo show whether the organisation's overall exposure is improving or worsening so leaders can judge programme effectiveness Correct
- BTo confirm that a single scanner plugin is correctly licensed for each subnet it touches
- CTo replace per-finding remediation records so individual tickets no longer need to be retained
- DTo calculate the exact CVSS base score for each newly published vulnerability before triage
Why A is correct: Comparing risk scores across periods reveals direction of travel, letting leaders see if remediation is outpacing new findings and whether investment is working.
Why B is wrong: Licensing checks are an operational housekeeping task unrelated to trends; the mention of subnets adds plausibility but does not describe why trends are reported.
Why C is wrong: Trend reporting summarises alongside detailed records; it never removes the need for them, so this is a tempting but incorrect efficiency claim.
Why D is wrong: CVSS base scoring is a per-finding scoring activity done at intake, not the aim of period-over-period trend reporting, though both involve scores.