QUALYS REPORTING STRATEGIES AND
BEST PRACTICES EXAM QUESTIONS
AND ANSWERS. VERIFIED 2025/2026.
In the patch report template, which evaluation provides the most accurate patches that need to
be installed?
(A) Superseded patch evaluation
(B) Latest patch evaluation
(C) QID based patch evaluation
(D) Classic patch evaluation - ANS (A) Superseded patch evaluation
Which scorecard report type allows you to identify hosts that are missing required patches and
software?***
(A) Patch report
(B) Vulnerability scorecard report
(C) Missing software report
(D) Asset Search Report - ANS (A) Patch report
1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.
, Which of the following scenarios can lead to gaps in the patch tree structure and break the
patch supersedence logic? Select all that apply.
(A) Scan report with vulnerability search list or Threat Protection RTI filter
(B) Cloud Agent data collection followed by an authenticated scan
(C) Scan job with a custom vulnerability filter
(D) Unauthenticated scan
(E) Cloud Agent scan - ANS (A) Scan report with vulnerability search list or Threat Protection
RTI filter
(C) Scan job with a custom vulnerability filter
Identify the vulnerability types excluded by default in the VM/VMDR Dashboard. Select all that
apply.***
(A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
(C) Vulnerabilities without exploits
(D) Low severity vulnerabilities
(E) Vulnerabilities without patches - ANS (A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
The ____________ vulnerability type is enabled by default in a new report template.
(A) Confirmed
(B) Potential
(C) Patched
(D) Information Gathered - ANS (B) Potential
2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.
BEST PRACTICES EXAM QUESTIONS
AND ANSWERS. VERIFIED 2025/2026.
In the patch report template, which evaluation provides the most accurate patches that need to
be installed?
(A) Superseded patch evaluation
(B) Latest patch evaluation
(C) QID based patch evaluation
(D) Classic patch evaluation - ANS (A) Superseded patch evaluation
Which scorecard report type allows you to identify hosts that are missing required patches and
software?***
(A) Patch report
(B) Vulnerability scorecard report
(C) Missing software report
(D) Asset Search Report - ANS (A) Patch report
1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.
, Which of the following scenarios can lead to gaps in the patch tree structure and break the
patch supersedence logic? Select all that apply.
(A) Scan report with vulnerability search list or Threat Protection RTI filter
(B) Cloud Agent data collection followed by an authenticated scan
(C) Scan job with a custom vulnerability filter
(D) Unauthenticated scan
(E) Cloud Agent scan - ANS (A) Scan report with vulnerability search list or Threat Protection
RTI filter
(C) Scan job with a custom vulnerability filter
Identify the vulnerability types excluded by default in the VM/VMDR Dashboard. Select all that
apply.***
(A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
(C) Vulnerabilities without exploits
(D) Low severity vulnerabilities
(E) Vulnerabilities without patches - ANS (A) Fixed vulnerabilities
(B) Disabled or Ignored vulnerabilities
The ____________ vulnerability type is enabled by default in a new report template.
(A) Confirmed
(B) Potential
(C) Patched
(D) Information Gathered - ANS (B) Potential
2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.