Vulnerability Management Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Vulnerability Management flashcards as text
A penetration tester uses exploitation to confirm that a vulnerability scanner finding is truly exploitable. How does this differ from a vulnerability assessment?
Answer: Penetration testing actively exploits vulnerabilities to confirm impact, while vulnerability assessment identifies and reports potential weaknesses
Penetration testing goes beyond identification by attempting to exploit vulnerabilities to demonstrate real-world impact, whereas vulnerability assessments enumerate and rate findings without exploitation.
Which vulnerability management lifecycle phase involves verifying that applied patches or configuration changes successfully closed the identified vulnerability?
Answer: Validation
Validation (verification) involves rescanning or retesting after remediation to confirm the vulnerability is no longer present.
An analyst notices that the vulnerability scanner is flagging a particular finding on a host every week despite a patch being applied a month ago. What should the analyst suspect?
Answer: The patch was not successfully applied or was rolled back
Persistent findings after patching most commonly indicate the patch did not apply correctly, was reverted, or the scan is targeting a different instance of the software.
Which of the following BEST describes the concept of 'attack surface reduction' as a vulnerability management strategy?
Answer: Eliminating unnecessary services, ports, and software to minimize the number of exploitable entry points
Attack surface reduction removes unused services, disables default accounts, and uninstalls unnecessary software to shrink the number of vectors an attacker can leverage.
When assessing vulnerabilities in a cloud IaaS environment, which responsibility typically remains with the customer rather than the cloud provider?
Answer: Guest OS and application-level vulnerabilities
Under the shared responsibility model in IaaS, the customer owns the guest OS, middleware, and applications — including patching them for vulnerabilities.
Which threat intelligence source provides near-real-time, community-contributed indicators of compromise (IOCs) and vulnerability information shared between organizations?
Answer: Information Sharing and Analysis Centers (ISACs)
ISACs facilitate trusted, industry-specific sharing of threat intelligence including active IOCs and exploitation activity among member organizations.
A security analyst is reviewing a vulnerability report and sees the term 'locally exploitable with high privileges required.' How should this affect prioritization compared to a remotely exploitable, no-privileges-required vulnerability?
Answer: It should generally be deprioritized relative to the remote, no-auth vulnerability because exploitation requires greater attacker access
Remote, unauthenticated vulnerabilities present a much wider attack surface and lower barrier to exploitation than local vulnerabilities requiring privileged access.