🌍 All Study Guides📊 Dashboard📰 Blog💡 About
Google Cybersecurity Professional Certificate • STUDY MODE

FLAWS IN THE SYSTEM

QUESTION 1 OF 7

Which of the following are steps in the vulnerability management process. Select two answers.

A
Catalog organizational assets
B
Prepare defenses against threatsCorrect Answer
C
Assign a CVE ID
D
Identify vulnerabilitiesCorrect Answer
Explanation:

Vulnerability management is an internal process that includes identifying vulnerabilities and preparing defenses against threats.

QUESTION 2 OF 7

An organization is attacked by a vulnerability that was previously unknown. What is this exploit an example of?

A
A cipher
B
A zero-dayCorrect Answer
C
An asset
D
A perimeter layer
Explanation:

A zero-day refers to an exploit that was previously unknown.

QUESTION 3 OF 7

Which layer of the defense in depth strategy is a user authentication layer that mainly filters external access?

A
PerimeterCorrect Answer
B
Data
C
Network
D
Endpoint
Explanation:

The perimeter layer consists of authentication technologies that let verified users in.

QUESTION 4 OF 7

A security researcher reports a new vulnerability to the CVE list. Which of the following criteria must the vulnerability meet before it receives a CVE ID? Select two answers.

A
The vulnerability must be unknown to the developer.
B
It must affect multiple applications.
C
The submission must have supporting evidence.Correct Answer
D
It must be independently fixable.Correct Answer
Explanation:

Criteria that must be met are that vulnerabilities should be independently fixable and must have supporting evidence.

QUESTION 5 OF 7

Which of the following are steps in the vulnerability management process? Select three answers.

A
Consider potential exploitsCorrect Answer
B
Identify vulnerabilitiesCorrect Answer
C
Prepare defenses against threatsCorrect Answer
D
Conduct zero-day exploits
Explanation:

Vulnerability management is a four-step process that includes the following steps: identify vulnerabilities, consider potential exploits, prepare defenses against threats, and evaluate those defenses.

QUESTION 6 OF 7

Which of the following is a layered approach to vulnerability management that reduces risk?

A
Separation of duties
B
OAuth
C
Defense in depthCorrect Answer
D
Asset management
Explanation:

Defense in depth is a layered approach to vulnerability management that reduces risk. It's a security approach that protects assets by surrounding them with multiple layers of protection.

QUESTION 7 OF 7

Which of the following criteria need to be met before qualifying for a CVE ID? Select three answers.

A
Vulnerabilities must be submitted with supporting evidence.Correct Answer
B
Vulnerabilities must only affect one codebase.Correct Answer
C
Vulnerabilities must be recognized as a potential security risk.Correct Answer
D
Vulnerabilities must be exploited prior to reporting.
Explanation:

Vulnerabilities must only affect a single codebase, be submitted with supporting evidence, and be recognized as potential security risks to qualify for a CVE ID. They must also be independent of other issues.

Ready to test your recall?

Which of the following are steps in the vulnerability management process. Select two answers.

💡Select all 2 correct answers before submitting (0 of 2 selected).
A
Catalog organizational assets
B
Prepare defenses against threats
C
Assign a CVE ID
D
Identify vulnerabilities

How confident are you in this answer?