FLAWS IN THE SYSTEM
Which of the following are steps in the vulnerability management process. Select two answers.
Vulnerability management is an internal process that includes identifying vulnerabilities and preparing defenses against threats.
An organization is attacked by a vulnerability that was previously unknown. What is this exploit an example of?
A zero-day refers to an exploit that was previously unknown.
Which layer of the defense in depth strategy is a user authentication layer that mainly filters external access?
The perimeter layer consists of authentication technologies that let verified users in.
A security researcher reports a new vulnerability to the CVE list. Which of the following criteria must the vulnerability meet before it receives a CVE ID? Select two answers.
Criteria that must be met are that vulnerabilities should be independently fixable and must have supporting evidence.
Which of the following are steps in the vulnerability management process? Select three answers.
Vulnerability management is a four-step process that includes the following steps: identify vulnerabilities, consider potential exploits, prepare defenses against threats, and evaluate those defenses.
Which of the following is a layered approach to vulnerability management that reduces risk?
Defense in depth is a layered approach to vulnerability management that reduces risk. It's a security approach that protects assets by surrounding them with multiple layers of protection.
Which of the following criteria need to be met before qualifying for a CVE ID? Select three answers.
Vulnerabilities must only affect a single codebase, be submitted with supporting evidence, and be recognized as potential security risks to qualify for a CVE ID. They must also be independent of other issues.
Ready to test your recall?
Which of the following are steps in the vulnerability management process. Select two answers.
How confident are you in this answer?