Module 12 Vulnerability Management
Arkady has been asked to provide an explanation for to a supervisor why the SOC is not
acting vulnerability scans constantly over all structures. Which of the subsequent would NOT
be a purpose Arkady could deliver? - ANS-fee
Artem has been requested to perceive an software protocol for changing cyber chance
intelligence over HTTPS. Which protocol would he pick? - ANS-TAXII
Bohdan is explaining to an intern some of the hazards to lively scanning. Which of the
following would Bohdan NOT supply as a drawback? - ANS-Active scanning can boost up
the collection of information.
Borysko wishes to specify which devices want to be included within the subsequent
vulnerability scan. What parameter should he set? - ANS-scope
Danylo is analyzing the outcomes of a vulnerability experiment and is prioritizing the list of
vulnerabilities. He wants to use a gadget that will assign a numeric score to each
vulnerability. Which machine will Danylo use? - ANS-CVSS
Isai wishes to continuously analyze apps for vulnerabilities and wishes a dashboard that the
security group can use to screen the packages' modern safety functions. What device could
Isai select? - ANS-bundle tracking
Kostyantyn has been asked to discover a part of the internet that is the area of hazard actors
to search for facts about the today's types of attacks. What area of the web will he discover?
- ANS-dark net
What is the first step that ought to be taken after deciding which vulnerability scanning tool to
apply? - ANS-Update the plug-ins
Where do third-birthday celebration assets get their chance intelligence records? - ANS-from
the statistics they acquire from their very own customers
Which of the subsequent do plug-ins NOT incorporate? - ANS-A listing of prone nearby IP
addresses
Which of the following does NOT practice to a vulnerability test? - ANS-Act like a risk actor
to find vulnerabilities to make the most.
Which of the subsequent is considered the pleasant-known and most extensively used
vulnerability scanner? - ANS-Nessus
Which of the following is NOT a project of running a vulnerability experiment? - ANS-low
volume of scan statistics
Arkady has been asked to provide an explanation for to a supervisor why the SOC is not
acting vulnerability scans constantly over all structures. Which of the subsequent would NOT
be a purpose Arkady could deliver? - ANS-fee
Artem has been requested to perceive an software protocol for changing cyber chance
intelligence over HTTPS. Which protocol would he pick? - ANS-TAXII
Bohdan is explaining to an intern some of the hazards to lively scanning. Which of the
following would Bohdan NOT supply as a drawback? - ANS-Active scanning can boost up
the collection of information.
Borysko wishes to specify which devices want to be included within the subsequent
vulnerability scan. What parameter should he set? - ANS-scope
Danylo is analyzing the outcomes of a vulnerability experiment and is prioritizing the list of
vulnerabilities. He wants to use a gadget that will assign a numeric score to each
vulnerability. Which machine will Danylo use? - ANS-CVSS
Isai wishes to continuously analyze apps for vulnerabilities and wishes a dashboard that the
security group can use to screen the packages' modern safety functions. What device could
Isai select? - ANS-bundle tracking
Kostyantyn has been asked to discover a part of the internet that is the area of hazard actors
to search for facts about the today's types of attacks. What area of the web will he discover?
- ANS-dark net
What is the first step that ought to be taken after deciding which vulnerability scanning tool to
apply? - ANS-Update the plug-ins
Where do third-birthday celebration assets get their chance intelligence records? - ANS-from
the statistics they acquire from their very own customers
Which of the subsequent do plug-ins NOT incorporate? - ANS-A listing of prone nearby IP
addresses
Which of the following does NOT practice to a vulnerability test? - ANS-Act like a risk actor
to find vulnerabilities to make the most.
Which of the subsequent is considered the pleasant-known and most extensively used
vulnerability scanner? - ANS-Nessus
Which of the following is NOT a project of running a vulnerability experiment? - ANS-low
volume of scan statistics