Vulnerability Management EXAM 1
Questions And Answers
What is a Risk? -
correct answer ✅a function of THREATS and VULNERABILITIES on a
per "asset" basis
What is the Risk formula? -
correct answer ✅Risk = Threats + Vulnerabilities - Safeguards
What are the 3 main threat sources? -
correct answer ✅- Structural Failures (like a leaking pipe in a
building that floods a server room, or a fire resulting of an electrical
problem)
- Environmental Disasters (like an earthquake, tornado, hurricane,
etc.)
- People (outsiders or insiders)
What is a vulnerability? -
correct answer ✅an inherent weakness
What is Vulnerability Management? -
correct answer ✅the practice of FINDING and MITIGATING the
vulnerabilities in computers and networks
,Vulnerability Management EXAM 1
Questions And Answers
True or False? VULNERABILITY MANAGEMENT comes down to
whether you want to remove the vulnerability (fix the problem), or
apply a safeguard(s) to offset the risk. -
correct answer ✅True
3 Ways to find vulnerabilities: -
correct answer ✅- ASSESS, AUDIT, or TEST
- MONITOR CONFIGURATIONS and CHANGE to determine what
vulnerabilities may be unintentionally created
- ANALYZE POTENTIAL ATTACKS which discloses vulnerabilities that
cannot be easily seen
What is an Assessment? -
correct answer ✅A SUBJECTIVE EVALUATION by a human to aid in
the DESIGN/RE-DESIGN of safeguards and can actually IMPACT
what the standards are
How does the proof work in Assessments? -
correct answer ✅ATTESTATIONS (i.e. declarations of evidence or
proof) are solicited (meaning you are just asking a person, not
actually checking yourself) and documented
,Vulnerability Management EXAM 1
Questions And Answers
What are the 3 main pros to Assessments? -
correct answer ✅- less INVASIVE and EXPENSIVE to complete than
an audit
- less TEDIOUS than an audit
- drives DESIGN and ARCHITECTURE instead of validation of
configuration
What is an Audit? -
correct answer ✅An OBJECTIVE EVALUATION by a human to
determine if the CONFIGURATION of safeguards is in alignment
with a DOCUMENTED STANDARD (purely checking to see if the
organizational/industry standards (e.g. PCI DSS) are being
followed).
How does proof work in Audits? -
correct answer ✅EVIDENCE of configuration is solicited and
DOCUMENTED (meaning you need to actually SEE THE PROOF via
screenshots or something)
What are some reference standards used in audits? -
correct answer ✅ORGANIZATIONAL policies, procedures, &
standards and/or INDUSTRY standards (e.g. PCI DSS)
, Vulnerability Management EXAM 1
Questions And Answers
What are the 2 pros to Audits? -
correct answer ✅- uncovers INITIAL IMPLEMENTATIONS or
changes that are not in ALIGNMENT with standards
- provides ASSURANCE to others
What is the main con to Audits? -
correct answer ✅the standard may not be SPECIFIC enough or may
be DATED in content, and thus only determines COMPLIANCE with
the standard and does not DETECT RISK
What is a Vulnerability Scan? -
correct answer ✅a TECHNICAL EVALUATION to determine if the
configuration of safeguards is in ALIGNMENT with a DOCUMENTED
STANDARD (lets TECHNOLOGY/SOFTWARE do the work for us)
How does proof work in a Vulnerability Scan? -
correct answer ✅EVIDENCE of configuration is TECHNICALLY
EXTRACTED, one system at a time and documented. Based on
vendor or public provided verification points.
Questions And Answers
What is a Risk? -
correct answer ✅a function of THREATS and VULNERABILITIES on a
per "asset" basis
What is the Risk formula? -
correct answer ✅Risk = Threats + Vulnerabilities - Safeguards
What are the 3 main threat sources? -
correct answer ✅- Structural Failures (like a leaking pipe in a
building that floods a server room, or a fire resulting of an electrical
problem)
- Environmental Disasters (like an earthquake, tornado, hurricane,
etc.)
- People (outsiders or insiders)
What is a vulnerability? -
correct answer ✅an inherent weakness
What is Vulnerability Management? -
correct answer ✅the practice of FINDING and MITIGATING the
vulnerabilities in computers and networks
,Vulnerability Management EXAM 1
Questions And Answers
True or False? VULNERABILITY MANAGEMENT comes down to
whether you want to remove the vulnerability (fix the problem), or
apply a safeguard(s) to offset the risk. -
correct answer ✅True
3 Ways to find vulnerabilities: -
correct answer ✅- ASSESS, AUDIT, or TEST
- MONITOR CONFIGURATIONS and CHANGE to determine what
vulnerabilities may be unintentionally created
- ANALYZE POTENTIAL ATTACKS which discloses vulnerabilities that
cannot be easily seen
What is an Assessment? -
correct answer ✅A SUBJECTIVE EVALUATION by a human to aid in
the DESIGN/RE-DESIGN of safeguards and can actually IMPACT
what the standards are
How does the proof work in Assessments? -
correct answer ✅ATTESTATIONS (i.e. declarations of evidence or
proof) are solicited (meaning you are just asking a person, not
actually checking yourself) and documented
,Vulnerability Management EXAM 1
Questions And Answers
What are the 3 main pros to Assessments? -
correct answer ✅- less INVASIVE and EXPENSIVE to complete than
an audit
- less TEDIOUS than an audit
- drives DESIGN and ARCHITECTURE instead of validation of
configuration
What is an Audit? -
correct answer ✅An OBJECTIVE EVALUATION by a human to
determine if the CONFIGURATION of safeguards is in alignment
with a DOCUMENTED STANDARD (purely checking to see if the
organizational/industry standards (e.g. PCI DSS) are being
followed).
How does proof work in Audits? -
correct answer ✅EVIDENCE of configuration is solicited and
DOCUMENTED (meaning you need to actually SEE THE PROOF via
screenshots or something)
What are some reference standards used in audits? -
correct answer ✅ORGANIZATIONAL policies, procedures, &
standards and/or INDUSTRY standards (e.g. PCI DSS)
, Vulnerability Management EXAM 1
Questions And Answers
What are the 2 pros to Audits? -
correct answer ✅- uncovers INITIAL IMPLEMENTATIONS or
changes that are not in ALIGNMENT with standards
- provides ASSURANCE to others
What is the main con to Audits? -
correct answer ✅the standard may not be SPECIFIC enough or may
be DATED in content, and thus only determines COMPLIANCE with
the standard and does not DETECT RISK
What is a Vulnerability Scan? -
correct answer ✅a TECHNICAL EVALUATION to determine if the
configuration of safeguards is in ALIGNMENT with a DOCUMENTED
STANDARD (lets TECHNOLOGY/SOFTWARE do the work for us)
How does proof work in a Vulnerability Scan? -
correct answer ✅EVIDENCE of configuration is TECHNICALLY
EXTRACTED, one system at a time and documented. Based on
vendor or public provided verification points.