QUALYS EXAM PREP TEST BANK VERIFIED
QUESTIONS AND CORRECT ANSWERS
●● Vulnerability Management
Answer: proactive activities
●● Sources of vulnerabilities
Answer: 1. Widespread use of employee VPN
2. Inconsistent adoption of cyber hygiene practices
3. Higher volume of alerts increase burden on IT staff
●● Vulnerability response
Answer: The process of identifying, classifying, and prioritizing
vulnerabilities.
- Requires an agile approach
●● Remediation (as a response)
Answer: change, patch, correct, mend, repair. Basically to reduce
vulnerability
●● No remediation (as a response)
,Answer: Just document the risk. Accept the consequences if cost of
remediation outweighs the business value
●● Infrastructure Vulnerability Response
Answer: managers vulnerabilities on Networked assets like servers,
network devices.
●● Application Vulnerability Response
Answer: manages vulnerabilities on custom-developed app.
●● Container Vulnerability Response
Answer: manages vulnerabilities on apps developed and deployed via
containers
●● Configuration Compliance
Answer: - manages vulnerabilities on misconfigured software
- Aggregates scan results from third-party configuration scanning apps
●● Operational Technology Vulnerability Response
Answer: manages vulnerabilities on OT assets at the site level
●● What does IVR protect?
Answer: Hardware, Software, OS, networks etc.
, ●● What does IVR create?
Answer: Vulnerability Items
●● What integration does IVR support?
Answer: Qualys, Tenable, Rapid7
●● IVR Information Sources
Answer: NVD : CVE
●● What does AVR protect?
Answer: Custom applications
●● What does AVR create?
Answer: Application Vulnerability Items. AVR associates a Vulnerability
with an application
●● What integration does AVR support?
Answer: Qualys, Veracode, Fortify
●● AVR Information Sources
Answer: Mitre: CWE
QUESTIONS AND CORRECT ANSWERS
●● Vulnerability Management
Answer: proactive activities
●● Sources of vulnerabilities
Answer: 1. Widespread use of employee VPN
2. Inconsistent adoption of cyber hygiene practices
3. Higher volume of alerts increase burden on IT staff
●● Vulnerability response
Answer: The process of identifying, classifying, and prioritizing
vulnerabilities.
- Requires an agile approach
●● Remediation (as a response)
Answer: change, patch, correct, mend, repair. Basically to reduce
vulnerability
●● No remediation (as a response)
,Answer: Just document the risk. Accept the consequences if cost of
remediation outweighs the business value
●● Infrastructure Vulnerability Response
Answer: managers vulnerabilities on Networked assets like servers,
network devices.
●● Application Vulnerability Response
Answer: manages vulnerabilities on custom-developed app.
●● Container Vulnerability Response
Answer: manages vulnerabilities on apps developed and deployed via
containers
●● Configuration Compliance
Answer: - manages vulnerabilities on misconfigured software
- Aggregates scan results from third-party configuration scanning apps
●● Operational Technology Vulnerability Response
Answer: manages vulnerabilities on OT assets at the site level
●● What does IVR protect?
Answer: Hardware, Software, OS, networks etc.
, ●● What does IVR create?
Answer: Vulnerability Items
●● What integration does IVR support?
Answer: Qualys, Tenable, Rapid7
●● IVR Information Sources
Answer: NVD : CVE
●● What does AVR protect?
Answer: Custom applications
●● What does AVR create?
Answer: Application Vulnerability Items. AVR associates a Vulnerability
with an application
●● What integration does AVR support?
Answer: Qualys, Veracode, Fortify
●● AVR Information Sources
Answer: Mitre: CWE