questions with answers |\ |\
vulnerability - CORRECT ANSWERS ✔✔A flaw or weakness
|\ |\ |\ |\ |\ |\ |\
that allows a threat agent to bypass security.
|\ |\ |\ |\ |\ |\ |\ |\
0-Day Vulnerability (Zero Day) - CORRECT ANSWERS ✔✔A
|\ |\ |\ |\ |\ |\ |\
vulnerability that is not known to the software developer
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
or vendor, but is known to an attacker
|\ |\ |\ |\ |\ |\ |\
Resources to information about vulnerabilities - CORRECT
|\ |\ |\ |\ |\ |\ |\
ANSWERS ✔✔NIST National Vulnerability Database
|\ |\ |\ |\
MITRE CVE |\
FEEDLY
CVSS (Common Vulnerability Scoring System) - CORRECT
|\ |\ |\ |\ |\ |\ |\
ANSWERS ✔✔A risk management approach to quantifying
|\ |\ |\ |\ |\ |\
vulnerability data and then taking into account the
|\ |\ |\ |\ |\ |\ |\ |\ |\
degree of risk to different types of systems or
|\ |\ |\ |\ |\ |\ |\ |\ |\
information.
3.0
Generate a score from 0-10 based on intrinsic
|\ |\ |\ |\ |\ |\ |\ |\
characteristics of the vuln. |\ |\ |\
, 0 = none
|\ |\
0.1=3.9 = low |\ |\
4.0-6.9 = medium |\ |\
7.0 - 8.9 -= high
|\ |\ |\ |\
9.0+ = critical |\ |\
CVE (Common Vulnerabilities and Exposures) - CORRECT
|\ |\ |\ |\ |\ |\ |\
ANSWERS ✔✔dictionary that provides a central repository |\ |\ |\ |\ |\ |\
of sec vuln's and issues
|\ |\ |\ |\ |\
Each CVE # represents a specific vulnerability
|\ |\ |\ |\ |\ |\
Types of Vulnerability Scans - CORRECT ANSWERS ✔✔▪
|\ |\ |\ |\ |\ |\ |\ |\
Discovery scan |\
▪ Full scan
|\ |\
▪ Stealth scan
|\ |\
▪ Compliance scan
|\ |\
▪Passive Scan |\
▪Active Scan |\ |\
▪Credentialed Scan |\
▪Non-credentialed scan |\
▪Agent-Based Scan |\
▪Assessment Scan |\