QUALYS VMDR CERTIFICATION
EVALUATION TEST 2026 FULL QUESTIONS
AND ANSWERS EXPERT VERIFIED
●● Which scorecard report type allows you to identify hosts that are
missing required patches and software?***
(A) Patch report
(B) Vulnerability scorecard report
(C) Missing software report
(D) Asset Search Report
Answer: (A) Patch report
●● Which of the following scenarios can lead to gaps in the patch tree
structure and break the patch supersedence logic? Select all that apply.
(A) Scan report with vulnerability search list or Threat Protection RTI
filter
(B) Cloud Agent data collection followed by an authenticated scan
(C) Scan job with a custom vulnerability filter
(D) Unauthenticated scan
(E) Cloud Agent scan
,Answer: (A) Scan report with vulnerability search list or Threat
Protection RTI filter
(C) Scan job with a custom vulnerability filter
●● Identify the vulnerability types excluded by default in the
VM/VMDR Dashboard. Select all that apply.***
(A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
(C) Vulnerabilities without exploits
(D) Low severity vulnerabilities
(E) Vulnerabilities without patches
Answer: (A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
●● The ____________ vulnerability type is enabled by default in a new
report template.
(A) Confirmed
(B) Potential
(C) Patched
(D) Information Gathered
Answer: (B) Potential
, ●● Stale asset and vulnerability data can affect your security risk and
business risk calculations. ***
(A) False
(B) True
Answer: (B) True
●● Adding non-Qualys user's email in the distribution group helps you
distribute the scheduled report to such users. ***
(A) True
(B) False
Answer: (A) True
●● When using host-based findings, which of these needs to be turned
on to toggle the inclusion of Fixed vulnerabilities in the report?***
(A) Trending
(B)
(C)
(D)
Answer: (A) Trending
EVALUATION TEST 2026 FULL QUESTIONS
AND ANSWERS EXPERT VERIFIED
●● Which scorecard report type allows you to identify hosts that are
missing required patches and software?***
(A) Patch report
(B) Vulnerability scorecard report
(C) Missing software report
(D) Asset Search Report
Answer: (A) Patch report
●● Which of the following scenarios can lead to gaps in the patch tree
structure and break the patch supersedence logic? Select all that apply.
(A) Scan report with vulnerability search list or Threat Protection RTI
filter
(B) Cloud Agent data collection followed by an authenticated scan
(C) Scan job with a custom vulnerability filter
(D) Unauthenticated scan
(E) Cloud Agent scan
,Answer: (A) Scan report with vulnerability search list or Threat
Protection RTI filter
(C) Scan job with a custom vulnerability filter
●● Identify the vulnerability types excluded by default in the
VM/VMDR Dashboard. Select all that apply.***
(A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
(C) Vulnerabilities without exploits
(D) Low severity vulnerabilities
(E) Vulnerabilities without patches
Answer: (A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
●● The ____________ vulnerability type is enabled by default in a new
report template.
(A) Confirmed
(B) Potential
(C) Patched
(D) Information Gathered
Answer: (B) Potential
, ●● Stale asset and vulnerability data can affect your security risk and
business risk calculations. ***
(A) False
(B) True
Answer: (B) True
●● Adding non-Qualys user's email in the distribution group helps you
distribute the scheduled report to such users. ***
(A) True
(B) False
Answer: (A) True
●● When using host-based findings, which of these needs to be turned
on to toggle the inclusion of Fixed vulnerabilities in the report?***
(A) Trending
(B)
(C)
(D)
Answer: (A) Trending