Vulnerability Management Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vulnerability Management flashcards as text
Which metric within the CVSS v3 Temporal Score group reflects whether a working exploit code is publicly available?
Answer: Exploit Code Maturity
Exploit Code Maturity (E) in the Temporal group indicates the current state of available exploit techniques, ranging from unproven to functional to weaponized.
An analyst receives an alert that a vulnerable version of Apache Struts is running on a production server. The CVE has a known weaponized exploit. What is the MOST urgent first step?
Answer: Immediately isolate the server and apply emergency patch procedures while monitoring for exploitation
A known weaponized exploit on a production system with network exposure demands immediate containment and emergency patching to prevent active exploitation.
What is the purpose of a vulnerability disclosure policy (VDP)?
Answer: To establish a formal, safe channel for external researchers to report security vulnerabilities to an organization
A VDP provides a legal and procedural safe harbor for security researchers to responsibly report vulnerabilities they discover in an organization's systems.
During vulnerability triage, an analyst identifies a vulnerability marked as 'informational' by the scanner. How should this be handled?
Answer: Informational findings reveal configuration or enumeration data that may aid attackers and should be reviewed for risk in context
Informational findings do not indicate a directly exploitable flaw but can expose system details useful for reconnaissance; analysts should assess whether they increase overall risk.
Which term describes a security weakness introduced by a developer leaving debugging code, hardcoded credentials, or undocumented functions in production software?
Answer: Backdoor / developer backdoor
Backdoors or developer backdoors are unintended or intentional access mechanisms left in production code that bypass normal authentication or authorization controls.
A company uses a bug bounty program as part of its vulnerability management strategy. What is the PRIMARY benefit of this approach?
Answer: It leverages the broader security research community to discover vulnerabilities that internal teams may miss
Bug bounty programs tap a diverse global pool of researchers with varied expertise and techniques, increasing the likelihood of finding complex vulnerabilities beyond internal team capacity.
When building a vulnerability management dashboard for executive reporting, which KPI MOST directly demonstrates program effectiveness over time?
Answer: Trend in mean time to remediate (MTTR) critical and high vulnerabilities
MTTR trend directly measures how quickly the organization closes critical risks, making it the most relevant indicator of vulnerability management program effectiveness for executives.