← All CSS Flashcard Decks

CSS Vulnerability Management & Penetration Testing Flashcards

6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CSS Vulnerability Management & Penetration Testing flashcards as text
  1. What is the purpose of a security baseline in vulnerability management?

    Answer: Defines the minimum acceptable security configuration for systems, providing a benchmark for deviation detection

    Security baselines document the required secure configuration state for systems, enabling teams to detect and remediate deviations that could introduce vulnerabilities.

  2. Which vulnerability management metric measures the average time between a patch being available and it being applied to production systems?

    Answer: Mean time to remediate (MTTR)

    MTTR for vulnerability management tracks how long vulnerabilities remain unpatched after fixes are available, a key indicator of patching efficiency.

  3. What is a red team exercise in cybersecurity?

    Answer: A full-scope, adversary-simulation engagement where a dedicated team attempts to breach an organization using real-world attack techniques

    Red team engagements simulate sophisticated, persistent adversaries to test the organization's detection, response, and resilience capabilities in a realistic way.

  4. What is responsible disclosure in the context of vulnerability research?

    Answer: Reporting discovered vulnerabilities privately to the vendor first, allowing time for a patch before public disclosure

    Responsible disclosure (coordinated vulnerability disclosure) gives vendors an agreed-upon window to develop and release a patch before the vulnerability is publicly disclosed.

  5. Which technique do attackers use to identify open ports and services on target systems during reconnaissance?

    Answer: Port scanning

    Port scanning sends packets to target ports and analyzes responses to identify which ports are open, filtered, or closed, revealing what services are running.

  6. What is the primary security concern with unmanaged or shadow IT assets in vulnerability management?

    Answer: They are unknown to security teams and therefore not included in scanning, patching, or monitoring programs

    Shadow IT assets — systems deployed without IT or security knowledge — create blind spots in vulnerability management programs, leaving them unpatched and unmonitored.