Tenable Vulnerability Management Specialist
1. What is the primary cloud-based platform for Tenable's vulnerability
management solution?
A. Tenable.sc
B. Tenable Nessus Professional
C. Nessus Manager
D. Tenable.io (Tenable Vulnerability Management)
2. Which scanning component is installed locally to reach internal, air-
gapped, or segmented networks that report results back to the cloud
platform?
A. Nessus Agent
B. Tenable.sc scanner
C. Nessus Network Monitor
D. Nessus scanner linked to Tenable Vulnerability Management
3. What is the primary purpose of a Nessus Agent?
A. To act as a proxy for cloud connector data
B. To perform lightweight, local vulnerability and compliance scans
directly on the host without requiring network credentials
C. To scan network traffic passively for asset discovery
D. To manage user permissions in Tenable Vulnerability Management
4. Which term describes Tenable's technology that continuously ingests data
from agents, scanners, and connectors without requiring a full active scan?
A. Predictive Prioritization
B. Lumin Exposure View
C. Frictionless Assessment
D. Container Security
Page 1 of 42
, Tenable Vulnerability Management Specialist
5. What does VPR stand for in Tenable's risk-scoring methodology?
A. Vulnerability Priority Rating
B. Vendor Patch Rating
C. Verified Priority Report
D. Vulnerability Patch Requirement
6. VPR scores are calculated on what numeric scale?
A. 0.1 to 10.0
B. 0 to 100
C. 1 to 5
D. 0 to 1000
7. Which of the following is NOT a factor Tenable uses to calculate a VPR
score?
A. Threat source and asset exposure
B. Age of the vulnerability
C. Threat intelligence and exploit activity
D. The organization's internal ticketing system priority field
8. What does CVSS stand for?
A. Critical Vulnerability Security Score
B. Central Vulnerability Severity Standard
C. Computed Vulnerability Severity Scale
D. Common Vulnerability Scoring System
9. What is the key difference between CVSS and VPR scoring?
A. VPR only applies to compliance checks
B. CVSS is dynamic and VPR is static
C. CVSS is exclusive to Tenable products
D. VPR incorporates real-time threat intelligence while CVSS is a
static severity measure
10. What is Asset Criticality Rating (ACR) used for in Tenable Vulnerability
Management?
A. To assign scan schedules automatically
B. To determine agent linking keys
C. To rate the severity of a specific plugin
Page 2 of 42
, Tenable Vulnerability Management Specialist
D. To indicate the relative business importance of an asset for
exposure calculations
11. Which Tenable product provides an organization-wide Cyber Exposure
score combining ACR and VPR data?
A. Tenable.sc
B. Nessus Professional
C. Tenable Container Security
D. Tenable Lumin
12. What is the function of a 'scan policy' in Tenable Vulnerability
Management?
A. A user permission profile
B. A reusable template defining scan settings such as plugins,
credentials, and performance options
C. A list of assets excluded from all future scans
D. A compliance audit report
13. Which scan template is best suited for a fast, unauthenticated overview
of live hosts on a network?
A. Host Discovery
B. Credentialed Patch Audit
C. Basic Network Scan
D. Advanced Scan
14. What is the main benefit of credentialed scanning over non-credentialed
scanning?
A. It scans faster than non-credentialed scans
B. It allows the scanner to log into the target and retrieve more
accurate, in-depth vulnerability and configuration data
C. It only works on cloud assets
D. It eliminates the need for plugin updates
15. Which protocol is most commonly used for credentialed scanning of
Windows hosts?
A. SMB (using WMI/registry access)
B. FTP
C. ICMP
Page 3 of 42
, Tenable Vulnerability Management Specialist
D. SNMP
16. Which protocol is most commonly used for credentialed scanning of
Linux/Unix hosts?
A. NetBIOS
B. RDP
C. SSH
D. SMB
17. What is a 'scan zone' in Tenable Vulnerability Management?
A. A dashboard widget filter
B. A category of vulnerability severity
C. A grouping of scanners assigned to scan specific IP ranges
D. A firewall rule set applied to scan traffic
18. What is the purpose of a linking key when deploying Nessus Agents?
A. It sets the scan frequency for the agent
B. It encrypts scan traffic between scanner and target
C. It authenticates and associates the agent with the correct Tenable
Vulnerability Management account
D. It licenses individual plugins
19. Agents can be organized for targeted scanning and reporting using which
feature?
A. Agent Groups
B. Scan Zones
C. Connector Groups
D. Access Groups
20. What is the recommended approach for scanning SCADA/ICS or other
fragile devices?
A. Use only agent-based scanning with maximum thread count
B. Disable safe checks to get full coverage
C. Always scan during business hours for accuracy
D. Use a scan policy with safe checks enabled and reduced scan
intensity
21. What does enabling 'Safe Checks' in a scan policy do?
Page 4 of 42
1. What is the primary cloud-based platform for Tenable's vulnerability
management solution?
A. Tenable.sc
B. Tenable Nessus Professional
C. Nessus Manager
D. Tenable.io (Tenable Vulnerability Management)
2. Which scanning component is installed locally to reach internal, air-
gapped, or segmented networks that report results back to the cloud
platform?
A. Nessus Agent
B. Tenable.sc scanner
C. Nessus Network Monitor
D. Nessus scanner linked to Tenable Vulnerability Management
3. What is the primary purpose of a Nessus Agent?
A. To act as a proxy for cloud connector data
B. To perform lightweight, local vulnerability and compliance scans
directly on the host without requiring network credentials
C. To scan network traffic passively for asset discovery
D. To manage user permissions in Tenable Vulnerability Management
4. Which term describes Tenable's technology that continuously ingests data
from agents, scanners, and connectors without requiring a full active scan?
A. Predictive Prioritization
B. Lumin Exposure View
C. Frictionless Assessment
D. Container Security
Page 1 of 42
, Tenable Vulnerability Management Specialist
5. What does VPR stand for in Tenable's risk-scoring methodology?
A. Vulnerability Priority Rating
B. Vendor Patch Rating
C. Verified Priority Report
D. Vulnerability Patch Requirement
6. VPR scores are calculated on what numeric scale?
A. 0.1 to 10.0
B. 0 to 100
C. 1 to 5
D. 0 to 1000
7. Which of the following is NOT a factor Tenable uses to calculate a VPR
score?
A. Threat source and asset exposure
B. Age of the vulnerability
C. Threat intelligence and exploit activity
D. The organization's internal ticketing system priority field
8. What does CVSS stand for?
A. Critical Vulnerability Security Score
B. Central Vulnerability Severity Standard
C. Computed Vulnerability Severity Scale
D. Common Vulnerability Scoring System
9. What is the key difference between CVSS and VPR scoring?
A. VPR only applies to compliance checks
B. CVSS is dynamic and VPR is static
C. CVSS is exclusive to Tenable products
D. VPR incorporates real-time threat intelligence while CVSS is a
static severity measure
10. What is Asset Criticality Rating (ACR) used for in Tenable Vulnerability
Management?
A. To assign scan schedules automatically
B. To determine agent linking keys
C. To rate the severity of a specific plugin
Page 2 of 42
, Tenable Vulnerability Management Specialist
D. To indicate the relative business importance of an asset for
exposure calculations
11. Which Tenable product provides an organization-wide Cyber Exposure
score combining ACR and VPR data?
A. Tenable.sc
B. Nessus Professional
C. Tenable Container Security
D. Tenable Lumin
12. What is the function of a 'scan policy' in Tenable Vulnerability
Management?
A. A user permission profile
B. A reusable template defining scan settings such as plugins,
credentials, and performance options
C. A list of assets excluded from all future scans
D. A compliance audit report
13. Which scan template is best suited for a fast, unauthenticated overview
of live hosts on a network?
A. Host Discovery
B. Credentialed Patch Audit
C. Basic Network Scan
D. Advanced Scan
14. What is the main benefit of credentialed scanning over non-credentialed
scanning?
A. It scans faster than non-credentialed scans
B. It allows the scanner to log into the target and retrieve more
accurate, in-depth vulnerability and configuration data
C. It only works on cloud assets
D. It eliminates the need for plugin updates
15. Which protocol is most commonly used for credentialed scanning of
Windows hosts?
A. SMB (using WMI/registry access)
B. FTP
C. ICMP
Page 3 of 42
, Tenable Vulnerability Management Specialist
D. SNMP
16. Which protocol is most commonly used for credentialed scanning of
Linux/Unix hosts?
A. NetBIOS
B. RDP
C. SSH
D. SMB
17. What is a 'scan zone' in Tenable Vulnerability Management?
A. A dashboard widget filter
B. A category of vulnerability severity
C. A grouping of scanners assigned to scan specific IP ranges
D. A firewall rule set applied to scan traffic
18. What is the purpose of a linking key when deploying Nessus Agents?
A. It sets the scan frequency for the agent
B. It encrypts scan traffic between scanner and target
C. It authenticates and associates the agent with the correct Tenable
Vulnerability Management account
D. It licenses individual plugins
19. Agents can be organized for targeted scanning and reporting using which
feature?
A. Agent Groups
B. Scan Zones
C. Connector Groups
D. Access Groups
20. What is the recommended approach for scanning SCADA/ICS or other
fragile devices?
A. Use only agent-based scanning with maximum thread count
B. Disable safe checks to get full coverage
C. Always scan during business hours for accuracy
D. Use a scan policy with safe checks enabled and reduced scan
intensity
21. What does enabling 'Safe Checks' in a scan policy do?
Page 4 of 42