問題文
A workload is reported both for an outdated library and for an overly permissive network setting. Why does the platform treat these as belonging to different risk domains?
選択肢
- Because one always carries a higher severity, whatever the published score of the flaw happens to say, than the other.
- Because one is detected by agentless collection and the other requires a Runtime Sensor, so the records can never appear for the same workload.
- Because one is a property of the software the workload runs and the other is a property of how the environment is configured around it, and they are fixed by different means.
- Because only one of them, the one about the configuration values, appears in compliance frameworks.