Vulnerability Management Module 12
Exam Questions 100% Verified Complete
Answers New Update
Which of the following is NOT a challenge of running a vulnerability
scan? -
correct answer ✅low volume of scan data
Where do third-party sources get their threat intelligence data? -
correct answer ✅from the information they collect from their own
customers
Which of the following is NOT true about threat intelligence? -
correct answer ✅Threat intelligence is especially vital to
penetration testing.
Why are open-source libraries vulnerable? -
correct answer ✅These libraries are not owned and controlled by
any single entity
Danylo is examining the results of a vulnerability scan and is
prioritizing the list of vulnerabilities. He wants to use a system that
will assign a numeric score to each vulnerability. Which system will
Danylo use? -
correct answer ✅CVSS
, Vulnerability Management Module 12
Exam Questions 100% Verified Complete
Answers New Update
What is the first step that should be taken after deciding which
vulnerability scanning tool to use? -
correct answer ✅Update the plug-ins
Artem has been asked to identify an application protocol for
exchanging cyber threat intelligence over HTTPS. Which protocol
would he choose? -
correct answer ✅TAXII
Kostyantyn has been asked to explore part of the web that is the
domain of threat actors to look for information about the latest
types of attacks. What area of the web will he explore? -
correct answer ✅dark web
Which of the following does NOT apply to a vulnerability scan? -
correct answer ✅Act like a threat actor to find vulnerabilities to
exploit.
Exam Questions 100% Verified Complete
Answers New Update
Which of the following is NOT a challenge of running a vulnerability
scan? -
correct answer ✅low volume of scan data
Where do third-party sources get their threat intelligence data? -
correct answer ✅from the information they collect from their own
customers
Which of the following is NOT true about threat intelligence? -
correct answer ✅Threat intelligence is especially vital to
penetration testing.
Why are open-source libraries vulnerable? -
correct answer ✅These libraries are not owned and controlled by
any single entity
Danylo is examining the results of a vulnerability scan and is
prioritizing the list of vulnerabilities. He wants to use a system that
will assign a numeric score to each vulnerability. Which system will
Danylo use? -
correct answer ✅CVSS
, Vulnerability Management Module 12
Exam Questions 100% Verified Complete
Answers New Update
What is the first step that should be taken after deciding which
vulnerability scanning tool to use? -
correct answer ✅Update the plug-ins
Artem has been asked to identify an application protocol for
exchanging cyber threat intelligence over HTTPS. Which protocol
would he choose? -
correct answer ✅TAXII
Kostyantyn has been asked to explore part of the web that is the
domain of threat actors to look for information about the latest
types of attacks. What area of the web will he explore? -
correct answer ✅dark web
Which of the following does NOT apply to a vulnerability scan? -
correct answer ✅Act like a threat actor to find vulnerabilities to
exploit.