Types of Vulnerability Assessment
Exam Actual Questions and Answers
2026
Active Assessment -
correct answer ✅A type of vulnerability assessment that uses
network scanners to identify the hosts, services, and vulnerabilities
present in a network. Active network scanners can reduce the
intrusiveness of the checks they perform.
External Assessment -
correct answer ✅external assessment examines the network from
a hacker's point of view to identify exploits and vulnerabilities
accessible to the outside world. These types of assessments use
external devices such as firewalls, routers, and servers. An external
assessment estimates the threat of network security attacks from
outside the organization. It determines the level of security of the
external network and firewall.
Passive Assessment -
correct answer ✅Passive assessments sniff the traffic present on
the network to identify the active systems, applications, and
vulnerabilities. Passive assessments also provide a list of the users
who are currently accessing the network
, Types of Vulnerability Assessment
Exam Actual Questions and Answers
2026
Internal Assessment -
correct answer ✅An internal assessment involves scrutinizing the
internal network to find exploits and vulnerabilities.
Host Based Assessment -
correct answer ✅A type of security check that involve conducting
a configuration-level check to identify system configurations, user
directories, file systems, registry settings, and other parameters to
evaluate the possibility of compromise.
Network-based Assessment -
correct answer ✅Determine the possible network security attacks
that may occur on an organization's system. These assessments
discover network resources and map the ports and services running
to various areas on the network.
Application Assessment -
correct answer ✅Focuses on transactional Web applications,
traditional client-server applications, and hybrid systems. Analyzes
all elements of an application infrastructure, including deployment
and communication within the client and server. Tests for
misconfiguration, outdated content, or known vulnerabilities.
Exam Actual Questions and Answers
2026
Active Assessment -
correct answer ✅A type of vulnerability assessment that uses
network scanners to identify the hosts, services, and vulnerabilities
present in a network. Active network scanners can reduce the
intrusiveness of the checks they perform.
External Assessment -
correct answer ✅external assessment examines the network from
a hacker's point of view to identify exploits and vulnerabilities
accessible to the outside world. These types of assessments use
external devices such as firewalls, routers, and servers. An external
assessment estimates the threat of network security attacks from
outside the organization. It determines the level of security of the
external network and firewall.
Passive Assessment -
correct answer ✅Passive assessments sniff the traffic present on
the network to identify the active systems, applications, and
vulnerabilities. Passive assessments also provide a list of the users
who are currently accessing the network
, Types of Vulnerability Assessment
Exam Actual Questions and Answers
2026
Internal Assessment -
correct answer ✅An internal assessment involves scrutinizing the
internal network to find exploits and vulnerabilities.
Host Based Assessment -
correct answer ✅A type of security check that involve conducting
a configuration-level check to identify system configurations, user
directories, file systems, registry settings, and other parameters to
evaluate the possibility of compromise.
Network-based Assessment -
correct answer ✅Determine the possible network security attacks
that may occur on an organization's system. These assessments
discover network resources and map the ports and services running
to various areas on the network.
Application Assessment -
correct answer ✅Focuses on transactional Web applications,
traditional client-server applications, and hybrid systems. Analyzes
all elements of an application infrastructure, including deployment
and communication within the client and server. Tests for
misconfiguration, outdated content, or known vulnerabilities.