Vulnerability Management Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vulnerability Management flashcards as text
Which metric in CVSSv3 indicates that an attacker must be on the same logical or physical network as the vulnerable system to exploit it?
Answer: Attack Vector: Adjacent
The Adjacent (A) attack vector requires the attacker to be on the same network segment or broadcast domain as the target.
A vulnerability scanner returns a finding with a CVSS base score of 9.8. Before prioritizing remediation, which contextual factor should a security analyst evaluate FIRST?
Answer: Whether the affected asset is internet-facing and stores sensitive data
Asset criticality and exposure context determine true business risk; a high CVSS score on an isolated, non-critical system may rank lower than a moderate score on an internet-facing critical asset.
What is the primary purpose of credentialed scanning versus unauthenticated scanning?
Answer: Credentialed scans can enumerate installed software, patch levels, and local configuration without relying on exposed network services
Providing scanner credentials allows it to log into hosts and inspect installed packages, registry settings, and configuration files, producing far more comprehensive and accurate results.
Which vulnerability remediation strategy involves deploying a temporary measure to reduce risk while a permanent patch is being developed or tested?
Answer: Compensating control
A compensating control (e.g., WAF rule, network ACL) reduces exploitability temporarily until a proper fix is available.
An analyst discovers that a critical vulnerability on a legacy PLC cannot be patched due to vendor support constraints. What is the MOST appropriate response?
Answer: Implement network segmentation and enhanced monitoring as compensating controls
When patching is not feasible, isolating the system via network segmentation and increasing monitoring reduces the attack surface and detection time.
Which type of vulnerability scan examines whether web application inputs are sanitized to prevent injection attacks without requiring source-code access?
Answer: Dynamic application security testing (DAST)
DAST tests a running application from the outside by sending malicious inputs to find injection, authentication, and configuration flaws.
A CySA+ analyst needs to prioritize hundreds of vulnerabilities. Which combination of factors BEST represents an effective risk-based prioritization model?
Answer: CVSS base score, asset criticality, and exploitability in the wild
Effective prioritization combines the technical severity (CVSS), business value of the asset, and whether active exploitation is occurring to focus remediation effort on the highest real-world risk.