Vulnerability Scanning and Analysis
CHAPTER 4 Exam Actual Questions
and Answers 2026
Which of the following is not a publicly accessible list used for
vulnerability research and analysis?
A. Common Vulnerabilities and Exposures (CVE)
B. The Japan Computer Emergency Response Team (JPCERT)
C. Common Weakness Enumeration (CWE)
D. Common Attack Pattern Enumeration and Classification (CAPEC) -
correct answer ✅B
Which of the following is a public, vendor-neutral forum and
mailing list that publishes vulnerability analysis details, exploitation
techniques, and other relevant information for the security
community?
A. US-CERT
B. MITRE
C. NIST
D. Full Disclosure -
correct answer ✅D
,Vulnerability Scanning and Analysis
CHAPTER 4 Exam Actual Questions
and Answers 2026
Which of the following is a major benefit of running a credentialed
vulnerability scan over a uncredentialed scan?
A. Uncredentialed vulnerability scans are known to more commonly
produce false positives.
B. Credentialed vulnerability scans more accurately represent real-
world conditions when facing an outside threat actor.
C. Uncredentialed vulnerability scans tend to reveal more issues, so
credentialed scans are easier to report.
D. Credentialed vulnerability scans are usually faster. -
correct answer ✅A
The National Institute of Standards and Technology (NIST)
maintains what public resource for analysis on vulnerabilities
published to the CVE dictionary, using the Common Vulnerability
Scoring System (CVSS)?
A. Full Disclosure
B. National Vulnerability Database (NVD)
C. CWE
, Vulnerability Scanning and Analysis
CHAPTER 4 Exam Actual Questions
and Answers 2026
D. OWASP -
correct answer ✅B
A discovery scan in nmap is described by which of the following
statements? (Choose two.)
A. It's an active scanning technique.
B. It scans all 65,000+ possible network ports.
C. It performs a simple ping test to determine if a host is up and
alive on the network.
D. It identifies software and versions running on open ports. -
correct answer ✅AC
A stealth scan in nmap is denoted by the __________ flag and
leverages the use of __________ when probing ports.
A. -sT, TCP Connect() calls
B. -sT, SYN packets
C. -sU, RST packets
CHAPTER 4 Exam Actual Questions
and Answers 2026
Which of the following is not a publicly accessible list used for
vulnerability research and analysis?
A. Common Vulnerabilities and Exposures (CVE)
B. The Japan Computer Emergency Response Team (JPCERT)
C. Common Weakness Enumeration (CWE)
D. Common Attack Pattern Enumeration and Classification (CAPEC) -
correct answer ✅B
Which of the following is a public, vendor-neutral forum and
mailing list that publishes vulnerability analysis details, exploitation
techniques, and other relevant information for the security
community?
A. US-CERT
B. MITRE
C. NIST
D. Full Disclosure -
correct answer ✅D
,Vulnerability Scanning and Analysis
CHAPTER 4 Exam Actual Questions
and Answers 2026
Which of the following is a major benefit of running a credentialed
vulnerability scan over a uncredentialed scan?
A. Uncredentialed vulnerability scans are known to more commonly
produce false positives.
B. Credentialed vulnerability scans more accurately represent real-
world conditions when facing an outside threat actor.
C. Uncredentialed vulnerability scans tend to reveal more issues, so
credentialed scans are easier to report.
D. Credentialed vulnerability scans are usually faster. -
correct answer ✅A
The National Institute of Standards and Technology (NIST)
maintains what public resource for analysis on vulnerabilities
published to the CVE dictionary, using the Common Vulnerability
Scoring System (CVSS)?
A. Full Disclosure
B. National Vulnerability Database (NVD)
C. CWE
, Vulnerability Scanning and Analysis
CHAPTER 4 Exam Actual Questions
and Answers 2026
D. OWASP -
correct answer ✅B
A discovery scan in nmap is described by which of the following
statements? (Choose two.)
A. It's an active scanning technique.
B. It scans all 65,000+ possible network ports.
C. It performs a simple ping test to determine if a host is up and
alive on the network.
D. It identifies software and versions running on open ports. -
correct answer ✅AC
A stealth scan in nmap is denoted by the __________ flag and
leverages the use of __________ when probing ports.
A. -sT, TCP Connect() calls
B. -sT, SYN packets
C. -sU, RST packets