QUALYS REPORTING STRATEGIES
COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
◍ Which Widget type always requires two queries?.
Answer: A)Venn
◍ Which of the following Report Templates is the best choice for viewing the
current status of all vulnerability findings (i.e., New, Active, Reopened,
Fixed)?.
Answer: B)Scan Report Template with Scan-based Findings enabled.
◍ Which Qualys sensors are responsible for collecting data for performing
vulnerability assessments and producing findings within Qualys VMDR?
(select two).
Answer: B)Cloud AgentD)Scanner Appliance
◍ What is required in order for Qualys to generate remediation tickets?.
Answer: Scan Results need to be processed by QualysA Policy needs to be
created
◍ About how many TCP ports are scanned when using Standard Scan option?.
Answer: 1900
◍ Which of the following risk indicators, measures the value of an asset and
the impact to your organization, if that asset is lost or stolen?.
Answer: A)Asset Criticality Score
◍ Which three features of the Vulnerability Management application can be
customized using a KnowledgeBase "Search List"?.
Answer: Report TemplatesRemediation PoliciesOption Profiles
◍ Dynamic Asset Tags are updated every time you..
, Answer: Run a scan
◍ Which setting (within Scan Report Template Findings) is required, to
include "Fixed" vulnerabilities in a report?.
Answer: C)Include Trending
◍ While Remediation Policies are designed to automate the "Exception
Handling" process, some features within VMDR allow you to accomplish
this task manually. Which VMDR features allow you to manually ignore
vulnerabilities, on specific assets? (select two).
Answer: B)VMDR Host Scan Report results (HTML format)D)VMDR
Asset Search Tab results
◍ When the "Host Not Alive" status is received from an asset, during a scan:.
Answer: B)Assessment testing is not performed and existing vulnerability
status is unchanged.
◍ Which item is not mandatory for launching a vulnerability scan?.
Answer: Authentication record
◍ Which of the following "Search List" criteria, are commonly used to align
report findings with organizational security goals and objectives. (select
three).
Answer: B)Qualys Severity LevelC)CVSS ScoreD)Real-time Threat
Indicator (RTI)
◍ Which of the following is NOT a component of a vulnerability scan?.
Answer: Host Discovery
◍ Which of the following components are included in the raw scan results,
assuming you do not apply a Search List to your Option Profile?.
Answer: Potential VulnerabilitiesInformation GatheredVulnerabilities
◍ By default, the first user added to a new Business Unit becomes a
____________ for that unit..
Answer: Unit manager
◍ To avoid patch supersedence miscalculations, which Patch Report Template
COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
◍ Which Widget type always requires two queries?.
Answer: A)Venn
◍ Which of the following Report Templates is the best choice for viewing the
current status of all vulnerability findings (i.e., New, Active, Reopened,
Fixed)?.
Answer: B)Scan Report Template with Scan-based Findings enabled.
◍ Which Qualys sensors are responsible for collecting data for performing
vulnerability assessments and producing findings within Qualys VMDR?
(select two).
Answer: B)Cloud AgentD)Scanner Appliance
◍ What is required in order for Qualys to generate remediation tickets?.
Answer: Scan Results need to be processed by QualysA Policy needs to be
created
◍ About how many TCP ports are scanned when using Standard Scan option?.
Answer: 1900
◍ Which of the following risk indicators, measures the value of an asset and
the impact to your organization, if that asset is lost or stolen?.
Answer: A)Asset Criticality Score
◍ Which three features of the Vulnerability Management application can be
customized using a KnowledgeBase "Search List"?.
Answer: Report TemplatesRemediation PoliciesOption Profiles
◍ Dynamic Asset Tags are updated every time you..
, Answer: Run a scan
◍ Which setting (within Scan Report Template Findings) is required, to
include "Fixed" vulnerabilities in a report?.
Answer: C)Include Trending
◍ While Remediation Policies are designed to automate the "Exception
Handling" process, some features within VMDR allow you to accomplish
this task manually. Which VMDR features allow you to manually ignore
vulnerabilities, on specific assets? (select two).
Answer: B)VMDR Host Scan Report results (HTML format)D)VMDR
Asset Search Tab results
◍ When the "Host Not Alive" status is received from an asset, during a scan:.
Answer: B)Assessment testing is not performed and existing vulnerability
status is unchanged.
◍ Which item is not mandatory for launching a vulnerability scan?.
Answer: Authentication record
◍ Which of the following "Search List" criteria, are commonly used to align
report findings with organizational security goals and objectives. (select
three).
Answer: B)Qualys Severity LevelC)CVSS ScoreD)Real-time Threat
Indicator (RTI)
◍ Which of the following is NOT a component of a vulnerability scan?.
Answer: Host Discovery
◍ Which of the following components are included in the raw scan results,
assuming you do not apply a Search List to your Option Profile?.
Answer: Potential VulnerabilitiesInformation GatheredVulnerabilities
◍ By default, the first user added to a new Business Unit becomes a
____________ for that unit..
Answer: Unit manager
◍ To avoid patch supersedence miscalculations, which Patch Report Template