Qualys Reporting Strategies and |\ |\ |\
Best Practices (Exam) questions
|\ |\ |\ |\
with answers
|\ |\
In the patch report template, which evaluation provides
|\ |\ |\ |\ |\ |\ |\ |\
the most accurate patches that need to be installed?
|\ |\ |\ |\ |\ |\ |\ |\
(A) Superseded patch evaluation
|\ |\ |\
(B) Latest patch evaluation
|\ |\ |\
(C) QID based patch evaluation
|\ |\ |\ |\
(D) Classic patch evaluation - CORRECT ANSWERS ✔✔(A)
|\ |\ |\ |\ |\ |\ |\ |\
Superseded patch evaluation |\ |\
Which scorecard report type allows you to identify hosts
|\ |\ |\ |\ |\ |\ |\ |\ |\
that are missing required patches and software?***
|\ |\ |\ |\ |\ |\
(A) Patch report
|\ |\
(B) Vulnerability scorecard report
|\ |\ |\
(C) Missing software report
|\ |\ |\
(D) Asset Search Report - CORRECT ANSWERS ✔✔(A)
|\ |\ |\ |\ |\ |\ |\ |\
Patch report |\
,Which of the following scenarios can lead to gaps in the
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\
patch tree structure and break the patch supersedence
|\ |\ |\ |\ |\ |\ |\ |\
logic? Select all that apply.
|\ |\ |\ |\
(A) Scan report with vulnerability search list or Threat
|\ |\ |\ |\ |\ |\ |\ |\ |\
Protection RTI filter |\ |\
(B) Cloud Agent data collection followed by an
|\ |\ |\ |\ |\ |\ |\ |\
authenticated scan |\
(C) Scan job with a custom vulnerability filter
|\ |\ |\ |\ |\ |\ |\
(D) Unauthenticated scan
|\ |\
(E) Cloud Agent scan - CORRECT ANSWERS ✔✔(A) Scan
|\ |\ |\ |\ |\ |\ |\ |\ |\
report with vulnerability search list or Threat Protection
|\ |\ |\ |\ |\ |\ |\ |\
RTI filter
|\
(C) Scan job with a custom vulnerability filter
|\ |\ |\ |\ |\ |\ |\
Identify the vulnerability types excluded by default in the
|\ |\ |\ |\ |\ |\ |\ |\ |\
VM/VMDR Dashboard. Select all that apply.***
|\ |\ |\ |\ |\
(A) Fixed vulnerabilities
|\ |\
(B) Disabled or Ignored vulnerabilities
|\ |\ |\ |\
(C) Vulnerabilities without exploits
|\ |\ |\
(D) Low severity vulnerabilities
|\ |\ |\
(E) Vulnerabilities without patches - CORRECT ANSWERS
|\ |\ |\ |\ |\ |\ |\
✔✔(A) Fixed vulnerabilities
|\ |\
, (B) Disabled or Ignored vulnerabilities
|\ |\ |\ |\
The ____________ vulnerability type is enabled by default
|\ |\ |\ |\ |\ |\ |\ |\
in a new report template.
|\ |\ |\ |\
(A) Confirmed
|\
(B) Potential
|\
(C) Patched
|\
(D) Information Gathered - CORRECT ANSWERS ✔✔(B)
|\ |\ |\ |\ |\ |\ |\
Potential
Stale asset and vulnerability data can affect your security
|\ |\ |\ |\ |\ |\ |\ |\ |\
risk and business risk calculations. ***
|\ |\ |\ |\ |\
(A) False
|\
(B) True - CORRECT ANSWERS ✔✔(B) True
|\ |\ |\ |\ |\ |\
Adding non-Qualys user's email in the distribution group
|\ |\ |\ |\ |\ |\ |\ |\
helps you distribute the scheduled report to such users.
|\ |\ |\ |\ |\ |\ |\ |\ |\
***
(A) True
|\
(B) False - CORRECT ANSWERS ✔✔(A) True
|\ |\ |\ |\ |\ |\
Best Practices (Exam) questions
|\ |\ |\ |\
with answers
|\ |\
In the patch report template, which evaluation provides
|\ |\ |\ |\ |\ |\ |\ |\
the most accurate patches that need to be installed?
|\ |\ |\ |\ |\ |\ |\ |\
(A) Superseded patch evaluation
|\ |\ |\
(B) Latest patch evaluation
|\ |\ |\
(C) QID based patch evaluation
|\ |\ |\ |\
(D) Classic patch evaluation - CORRECT ANSWERS ✔✔(A)
|\ |\ |\ |\ |\ |\ |\ |\
Superseded patch evaluation |\ |\
Which scorecard report type allows you to identify hosts
|\ |\ |\ |\ |\ |\ |\ |\ |\
that are missing required patches and software?***
|\ |\ |\ |\ |\ |\
(A) Patch report
|\ |\
(B) Vulnerability scorecard report
|\ |\ |\
(C) Missing software report
|\ |\ |\
(D) Asset Search Report - CORRECT ANSWERS ✔✔(A)
|\ |\ |\ |\ |\ |\ |\ |\
Patch report |\
,Which of the following scenarios can lead to gaps in the
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\
patch tree structure and break the patch supersedence
|\ |\ |\ |\ |\ |\ |\ |\
logic? Select all that apply.
|\ |\ |\ |\
(A) Scan report with vulnerability search list or Threat
|\ |\ |\ |\ |\ |\ |\ |\ |\
Protection RTI filter |\ |\
(B) Cloud Agent data collection followed by an
|\ |\ |\ |\ |\ |\ |\ |\
authenticated scan |\
(C) Scan job with a custom vulnerability filter
|\ |\ |\ |\ |\ |\ |\
(D) Unauthenticated scan
|\ |\
(E) Cloud Agent scan - CORRECT ANSWERS ✔✔(A) Scan
|\ |\ |\ |\ |\ |\ |\ |\ |\
report with vulnerability search list or Threat Protection
|\ |\ |\ |\ |\ |\ |\ |\
RTI filter
|\
(C) Scan job with a custom vulnerability filter
|\ |\ |\ |\ |\ |\ |\
Identify the vulnerability types excluded by default in the
|\ |\ |\ |\ |\ |\ |\ |\ |\
VM/VMDR Dashboard. Select all that apply.***
|\ |\ |\ |\ |\
(A) Fixed vulnerabilities
|\ |\
(B) Disabled or Ignored vulnerabilities
|\ |\ |\ |\
(C) Vulnerabilities without exploits
|\ |\ |\
(D) Low severity vulnerabilities
|\ |\ |\
(E) Vulnerabilities without patches - CORRECT ANSWERS
|\ |\ |\ |\ |\ |\ |\
✔✔(A) Fixed vulnerabilities
|\ |\
, (B) Disabled or Ignored vulnerabilities
|\ |\ |\ |\
The ____________ vulnerability type is enabled by default
|\ |\ |\ |\ |\ |\ |\ |\
in a new report template.
|\ |\ |\ |\
(A) Confirmed
|\
(B) Potential
|\
(C) Patched
|\
(D) Information Gathered - CORRECT ANSWERS ✔✔(B)
|\ |\ |\ |\ |\ |\ |\
Potential
Stale asset and vulnerability data can affect your security
|\ |\ |\ |\ |\ |\ |\ |\ |\
risk and business risk calculations. ***
|\ |\ |\ |\ |\
(A) False
|\
(B) True - CORRECT ANSWERS ✔✔(B) True
|\ |\ |\ |\ |\ |\
Adding non-Qualys user's email in the distribution group
|\ |\ |\ |\ |\ |\ |\ |\
helps you distribute the scheduled report to such users.
|\ |\ |\ |\ |\ |\ |\ |\ |\
***
(A) True
|\
(B) False - CORRECT ANSWERS ✔✔(A) True
|\ |\ |\ |\ |\ |\