Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 56 pages
Exam (elaborations)

CompTIA Network Vulnerability Assessment Professional (CNVP) – Advanced Practice Exam a well detailed one 2025 / 2026 written and graded A+ upgraded

Document preview thumbnail
Preview 4 out of 56 pages

CompTIA Network Vulnerability Assessment Professional (CNVP) – Advanced Practice Exam a well detailed one 2025 / 2026 written and graded A+ upgraded

Content preview

1




CompTIA Network
Vulnerability Assessment
Professional (CNVP) –
Advanced Practice Exam
a well detailed one 2025
/ 2026 written and
graded A+ upgraded


Exam Title: CompTIA Network Vulnerability Assessment Professional (CNVP) – Comprehensive
Advanced Practice Examination

, 2



Target Audience: IT professionals with 2–5 years of experience in network security, vulnerability
analysts, penetration testers, and security consultants

Difficulty Level: Advanced / Mixed (ranging from intermediate to expert-level questions)

Total Questions: 150 Multiple-Choice Questions



Section 1: Vulnerability Assessment Fundamentals (Questions 1–20)

1. A security analyst is tasked with conducting a network vulnerability assessment for a
financial institution. Which of the following BEST describes the primary objective of a
vulnerability assessment versus a penetration test?

A) Vulnerability assessments actively exploit weaknesses while penetration tests only identify
them
B) Vulnerability assessments identify, quantify, and prioritize vulnerabilities, while penetration
tests simulate real-world attacks to exploit weaknesses
C) Both processes are identical and the terms can be used interchangeably
D) Vulnerability assessments are performed only by automated tools, while penetration tests
are always manual

-” detailed answer 100 % correct :-”B
Rationale: Vulnerability assessments focus on identifying, quantifying, and prioritizing
vulnerabilities across systems, whereas penetration testing actively exploits weaknesses to
simulate real-world attacks.



2. During a vulnerability scan, a network administrator discovers that a critical server has an
unpatched vulnerability with a CVSS base score of 9.8. Which of the following statements
about the CVSS score is MOST accurate?

A) The score indicates the vulnerability's severity based on intrinsic characteristics that are
constant over time
B) The score represents the actual business risk to the organization
C) The score is calculated using only environmental metrics specific to the organization
D) The score ranges from 1 to 5, with 5 being the most severe

-” detailed answer 100 % correct :-”A
Rationale: CVSS base scores measure severity based on intrinsic characteristics of

, 3



vulnerabilities—factors that remain constant over time and across user environments.
Environmental and temporal metrics provide additional context for organizational risk.



3. A vulnerability analyst is reviewing scan results and finds numerous "critical" findings.
Which of the following should be the FIRST step in prioritizing remediation efforts?

A) Remediate all critical findings immediately regardless of context
B) Disable the affected systems until all vulnerabilities are patched
C) Validate findings, eliminate false positives, and correlate vulnerabilities with asset criticality
and exploitability
D) Escalate all findings to senior management without further analysis

-” detailed answer 100 % correct :-”C
Rationale: Prioritization requires validating findings, removing false positives, and assessing
vulnerabilities based on asset criticality, exploitability, and potential business impact.



4. An organization is required to comply with PCI DSS. Which of the following vulnerability
assessment activities does PCI DSS explicitly require?

A) Annual vulnerability assessments only
B) Quarterly vulnerability scans and annual penetration tests
C) Monthly vulnerability scans with no penetration testing requirement
D) Continuous real-time vulnerability monitoring only

-” detailed answer 100 % correct :-”B
Rationale: PCI DSS requires quarterly external and internal vulnerability scans and annual
penetration tests to protect cardholder data.



5. Which of the following BEST describes the difference between authenticated and
unauthenticated vulnerability scanning?

A) Authenticated scanning uses default credentials; unauthenticated scanning uses custom
credentials
B) Authenticated scanning provides deeper visibility by logging into systems and checking
configurations, while unauthenticated scanning simulates an external attacker's view
C) Unauthenticated scanning is always more accurate than authenticated scanning
D) Authenticated scanning can only be performed during business hours

, 4



-” detailed answer 100 % correct :-”B
Rationale: Authenticated scans use valid credentials to access systems and provide deeper
visibility into configurations and missing patches. Unauthenticated scans show what an external
attacker could discover—open ports, exposed services, and detectable software versions.



6. A security team is selecting a vulnerability scanning tool. Which of the following tools is an
open-source vulnerability scanner that uses a comprehensive library of network vulnerability
tests (NVTs)?

A) Nessus
B) Qualys
C) OpenVAS
D) Burp Suite

-” detailed answer 100 % correct :-”C
Rationale: OpenVAS (Greenbone) is an open-source vulnerability scanner that uses a
comprehensive library of network vulnerability tests to identify vulnerabilities across software
and servers.



7. During a vulnerability assessment, an analyst encounters a "false positive." Which of the
following BEST describes this scenario?

A) A vulnerability that exists but was not detected by the scanner
B) A security flaw that was successfully exploited during testing
C) A vulnerability that was reported by the scanner but does not actually exist
D) A vulnerability that was patched but remains in the vulnerability database

-” detailed answer 100 % correct :-”C
Rationale: A false positive occurs when a vulnerability scanner incorrectly reports the presence
of a flaw that does not actually exist. False positives increase noise for security teams and waste
resources.



8. Which CVSS metric group measures vulnerability characteristics that change over time,
such as the availability of exploit code?

A) Base metrics
B) Temporal metrics

Document information

Uploaded on
July 25, 2026
Number of pages
56
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$28.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions