CSS Vulnerability Management & Penetration Testing Flashcards
6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CSS Vulnerability Management & Penetration Testing flashcards as text
What does the Common Vulnerability Scoring System (CVSS) measure?
Answer: The severity of security vulnerabilities using a standardized numerical score from 0 to 10
CVSS assigns numerical scores to vulnerabilities based on metrics such as attack vector, complexity, privileges required, and impact, enabling consistent prioritization.
What is the difference between a vulnerability scan and a penetration test?
Answer: A vulnerability scan identifies known weaknesses automatically; a penetration test actively attempts to exploit them
Vulnerability scanning uses automated tools to identify potential weaknesses, while penetration testing involves skilled professionals who attempt to exploit those weaknesses to assess real impact.
What is a zero-day vulnerability?
Answer: A vulnerability that is unknown to the software vendor and has no available patch
A zero-day vulnerability is one that the vendor is unaware of, meaning there are zero days between discovery and exploitation — no patch exists yet.
Which penetration testing phase involves gathering information about the target without directly interacting with its systems?
Answer: Passive reconnaissance
Passive reconnaissance collects publicly available information (OSINT) about the target without sending any traffic to its systems, making it harder to detect.
What is the purpose of patch management in vulnerability management?
Answer: Systematically identifies, tests, and deploys software updates to remediate known vulnerabilities
Patch management reduces the attack surface by ensuring that known vulnerabilities in software and firmware are remediated in a timely, tested manner.
What does 'attack surface reduction' mean in vulnerability management?
Answer: Minimizing the number of exposed entry points that attackers could exploit
Attack surface reduction involves disabling unnecessary services, ports, and features to shrink the number of potential attack vectors available to adversaries.