CVE Assessment & Patch Management Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CVE Assessment & Patch Management flashcards as text
Which vulnerability management framework uses 'Required Action' deadlines and is enforced by CISA for US federal agencies?
Answer: CISA Known Exploited Vulnerabilities (KEV) catalog
The CISA KEV catalog lists vulnerabilities with evidence of active exploitation and mandates remediation deadlines for US federal civilian agencies under BOD 22-01.
A security engineer needs to determine if a CVE affects their environment without a scanner. Which artifact provides the most authoritative list of affected product versions?
Answer: The vendor security advisory and associated CPE list in the NVD entry
Vendor security advisories combined with NVD CPE data provide authoritative, versioned product lists to determine applicability without relying on scanner output.
What risk does applying a cumulative patch rollup introduce compared to individual patches?
Answer: It may include previously deferred patches that were intentionally skipped due to compatibility concerns
Cumulative rollups bundle multiple patches together, which may force installation of previously excluded patches, potentially reintroducing compatibility issues that were carefully managed.
In patch management, what is the primary purpose of maintaining a Software Bill of Materials (SBOM)?
Answer: To enable rapid identification of which systems are affected when a CVE is published for a specific component
An SBOM catalogs all software components and dependencies in an application, enabling security teams to quickly identify exposure when a new CVE targets a specific library or component.
Which scenario represents a 'virtual patch' or 'shield' in patch management?
Answer: A WAF or IPS rule that blocks exploitation of a vulnerability without modifying the vulnerable system itself
A virtual patch uses a WAF, IPS, or network control to detect and block exploit attempts against a vulnerability, providing protection when the actual system patch cannot be immediately applied.
When a CVE has a CVSS Base Score of 9.8 but the organization's risk-based assessment downgrades priority, which factor MOST justifies that decision?
Answer: The vulnerable service is not exposed to untrusted networks and no compensating controls are bypassed
Even a Critical CVE poses reduced risk if the vulnerable component is isolated from attack vectors (e.g., no internet exposure, network segmentation), justifying lower remediation urgency.
Which patch management process step ensures that applied patches have not been tampered with during distribution?
Answer: Cryptographic hash or digital signature verification of patch packages before installation
Verifying SHA-256 hashes or vendor digital signatures before applying patches ensures the patch package has not been modified or corrupted in transit, preventing supply-chain tampering.