Study Guide | Graded A+
1. If an organization identifies a critical vulnerability but does not prioritize it,
what potential risks could arise?
Increased likelihood of exploitation and potential data breaches.
Reduced costs associated with vulnerability management.
No risks, as vulnerabilities are managed at a later stage.
Improved security posture due to delayed action.
2. Which type of scan uses a copy of the network traffic to find vulnerabilities?
Non-Credentialed Scan
Agent-Based Scan
Server-Based Scan
Passive Scan
3. Describe how agent-based scanning differs from other scanning methods in
vulnerability management.
Agent-based scanning does not require any software installation.
Agent-based scanning is less accurate than network-based scanning
methods.
Agent-based scanning involves installing software on each target to
perform assessments, while other methods may not require such
installations.
Agent-based scanning only scans external networks, whereas other
methods scan internal systems.
,4. Describe the role of the NIST National Vulnerability Database in vulnerability
management.
The NIST National Vulnerability Database is a tool for scanning
networks for vulnerabilities.
The NIST National Vulnerability Database provides essential
information about vulnerabilities that helps organizations manage
and mitigate security risks.
The NIST National Vulnerability Database focuses on incident
response strategies.
The NIST National Vulnerability Database offers guidelines for
developing secure software.
5. What is one common remediation action taken to address vulnerabilities?
Patching software
Increasing network bandwidth
Upgrading hardware
Implementing new software
6. What is the Common Vulnerabilities and Exposures (CVE) used by the MITRE
Corporation?
It is a database of virus signatures.
It is a database of malware signatures.
It is a list of response mechanisms to known threats.
It is a dictionary of CVE Identifiers for publicly known cybersecurity
vulnerabilities.
,7. What does a false positive indicate in the context of vulnerability scanning?
A scanner fails to detect a vulnerability.
A vulnerability is confirmed to be present.
A vulnerability exists when it does not.
A vulnerability is accurately identified.
8. You recently completed a vulnerability scan on a database server. The scan
didn't report any issues. However, you know that it is missing a patch. The
patch wasn't applied because it causes problems with the database
application. Which of the following BEST describes this?
Non-credentialed scan
False positive
Credential scan
False negative
9. Which scan effects network traffic the least?
Passive Scan
Agent-Based Scan
Non-Credentialed Scan
Server-Based Scan
10. Which answer BEST describes the purpose of CVE?
A dictionary of known patterns of cyberattacks used by hackers.
Strives to create commonality in descriptions of weaknesses in
security software.
, A valuable site that belongs to a large governmental organization.
A list of standardized identifiers for known software vulnerabilities
and exposures.
11. Another popular method for identifying vulnerabilities in systems and
devices is through a vulnerability scan. A vulnerability scanner is software that
can be used to identify vulnerabilities on a system. The scan can be done in
two ways. Which one is described here? This type of scanner sends probes to
the system and evaluates a vulnerability based on the system response. It can
be used together with some type of system credentials or without them.
Passive scanner
Active scanner
12. What is a flaw or weakness that allows a threat agent to bypass security?
risk
threat
vulnerability
asset
13. List the stages of the vulnerability management lifecycle.
identify, analyze, report, fix, test, and monitor
discover, prioritize, mitigate, report, and verify
define, prioritize, assess, report, remediate, verify, and improve
scan, analyze, patch, verify, and document
14. What is the Common Vulnerability Scoring System (CVSS)?
A scoring system for exploits.