← All CySA+ Test Flashcard Decks

Vulnerability Management Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Vulnerability Management flashcards as text
  1. Which CVSS v3 metric describes the conditions beyond the attacker's control that must exist for a vulnerability to be exploited, such as a race condition or a specific system state?

    Answer: Attack Complexity

    Attack Complexity (AC) captures prerequisite conditions outside attacker control — High AC means the attacker must meet additional circumstances like timing or configuration.

  2. What does a 'false negative' mean in the context of vulnerability scanning?

    Answer: The scanner fails to detect a vulnerability that is actually present

    A false negative is a missed detection — the real vulnerability exists on the target but the scanner does not flag it, often due to scan limitations or evasion.

  3. An organization scans its environment weekly but new vulnerabilities are continuously introduced through software deployments. Which process BEST addresses this gap?

    Answer: Integrating vulnerability scanning into the CI/CD pipeline

    Embedding scanning into CI/CD pipelines ensures every build is tested before it reaches production, addressing the gap that periodic scans miss newly deployed code.

  4. Which document formally records that an organization has acknowledged a vulnerability and chosen not to remediate it based on business justification?

    Answer: Risk register entry with accepted risk notation

    Accepted risks are documented in the risk register with the business owner's sign-off, providing an audit trail for why known vulnerabilities were not remediated.

  5. During a vulnerability assessment, the analyst finds an open service on port 8080 returning a banner that identifies an outdated web server version. What is the analyst's next BEST action?

    Answer: Correlate the version with known CVEs and assess exploitability in context

    Banner information identifies software version; the analyst should look up CVEs for that version and evaluate whether the vulnerability is exploitable given the environment.

  6. Which scanning technique sends specially crafted packets to elicit responses that reveal OS and service version information without authentication?

    Answer: Active fingerprinting

    Active fingerprinting (e.g., Nmap OS detection) probes target systems with specific packets and analyzes responses to identify OS, services, and versions.

  7. A vulnerability management program reports that mean time to remediate (MTTR) critical vulnerabilities has increased from 7 days to 21 days over the past quarter. What is the MOST likely root cause to investigate first?

    Answer: The patch deployment process or change management workflow has a bottleneck

    An increasing MTTR typically signals a bottleneck in the patching or change management process — approvals, testing cycles, or resource constraints are slowing remediation.