Latest Study Guide
1. In a scenario where a new device is added to the network, which type of
asset list would best ensure that the vulnerability assessment reflects this
change immediately?
Historical asset list
Manual asset list
Dynamic asset list
Static asset list
2. Which option is the purpose of port scanning?
Identify legitimate users of a system.
Identify the Internet Protocol of the target system.
Determine if the network is up or down
Identify which ports and services are open on the target host.
3. What does the conditions section in alerts specify?
It lists the hardware requirements for alert generation.
It defines the user roles that can manage alerts.
It identifies what must be present in existing security data to trigger
an alert.
It outlines the types of alerts that can be generated.
4. What are the two essential components that every report in Tenable.sc must
include?
, A summary and conclusion.
A title and report type.
An author and date.
A list of vulnerabilities.
5. Describe the role of compliance scan policies in the context of Tenable.sc's
security management.
Compliance scan policies help ensure that systems meet regulatory
and organizational standards.
Compliance scan policies focus on hardware requirements for
deployment.
Compliance scan policies are used to manage user access to the
system.
Compliance scan policies are primarily for generating reports on
vulnerabilities.
6. Describe the significance of executing a scan policy in the compliance scan
process.
Executing a scan policy is crucial as it determines which
vulnerabilities are assessed against the defined assets.
Executing a scan policy is only necessary for initial setup.
Executing a scan policy only affects the user management settings.
Executing a scan policy is optional and can be skipped if assets are
already defined.
,7. If you were tasked with creating a report in Tenable.sc for a recent
vulnerability assessment, what key elements would you ensure are included
to meet the reporting requirements?
Only the list of vulnerabilities found.
A summary of the network configuration.
User management details and compliance policies.
A title and report type.
8. Describe how vulnerability data influences remediation efforts in security
assessments.
Vulnerability data highlights specific weaknesses, allowing
organizations to prioritize and address the most critical issues.
Vulnerability data only identifies potential threats without suggesting
actions.
Vulnerability data is irrelevant to security assessments.
Vulnerability data is used to generate compliance reports without
influencing remediation.
9. Describe the significance of adjusting port scanning options in host
discovery.
Adjusting port scanning options is unnecessary as all ports are
scanned by default.
Adjusting port scanning options only affects the speed of the scan,
not the results.
Adjusting port scanning options allows for targeted scanning,
improving efficiency and accuracy in identifying active services.
, Adjusting port scanning options increases the number of false
positives in the scan results.
10. What does an LDAP asset list query do in relation to an LDAP/AD server?
Retrieves a list of assets from an LDAP/AD server, updating every 12
hours.
Generates compliance reports from the LDAP/AD server.
Creates new user accounts in the LDAP/AD server.
Deletes outdated assets from the LDAP/AD server.
11. What type of scans should be performed when credentials are available?
Credentialed scans
Manual scans
External scans
Non-credentialed scans
12. Describe the importance of user management in the context of Tenable.sc.
User management is only important for compliance purposes.
User management is crucial for controlling access and ensuring
that only authorized personnel can perform vulnerability
assessments and manage configurations.
User management is irrelevant to Tenable.sc's functionality.
User management is primarily about creating user accounts without
security implications.
13. What is the recommended number of Nessus scanners for scanning 1000
hosts?