FedRAMP Vulnerability Management
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is vulnerability management?
A. A one-time scan before release.
B. An ongoing process for identifying, analyzing, prioritizing, remediating, validating, and reporting weaknesses.
C. A replacement for all security controls.
D. A list of unrelated software features.
2. Why is vulnerability management important in a FedRAMP context?
A. It supports continuous monitoring, risk awareness, remediation tracking, and evidence-based decision-making.
B. It removes the need for authorization boundaries.
C. It guarantees no future vulnerabilities will appear.
D. It replaces incident response.
3. What is the difference between scanning and vulnerability management?
A. They are exactly the same thing.
B. Vulnerability management only means storing scan files.
C. Scanning identifies potential findings; vulnerability management turns findings into triage, ownership, remediation, validation, reporting, and risk decisions.
D. Scanning replaces remediation.
4. Why does the authorization boundary matter?
A. It only affects visual diagrams.
B. It eliminates all customer responsibilities.
C. It guarantees every vulnerability is false.
D. It defines which systems, components, services, dependencies, and responsibilities are in scope.
5. Why is asset inventory important for vulnerability management?
A. Teams cannot reliably scan, assign, remediate, or report on assets they do not know exist.
B. Inventory automatically patches systems.
C. Inventory replaces scan validation.
D. Inventory is only useful for billing.
6. Why can authenticated scanning be valuable?
A. It always proves exploitability.
B. It replaces all manual review.
C. It can provide deeper visibility into installed software, patches, configurations, and local weaknesses.
D. It eliminates false positives completely.
7. Which source can help identify vulnerable third-party software components?
A. A color palette.
B. Software composition analysis or dependency scanning.
C. A marketing slogan.
D. A course transcript.
8. Why are cloud posture findings relevant?
A. They only affect logo placement.
B. They are never security relevant.
C. They replace vulnerability remediation.
D. Misconfigurations can create exposure even when software patches are current.
9. What should prioritization consider besides scanner severity?
A. Asset criticality, exploitability, exposure, data sensitivity, compensating controls, and operational context.
B. Only the order findings appear in a report.
C. Only file name length.
D. Only dashboard color.
10. What is a false positive?
A. A finding that has already been exploited.
B. A finding with no owner.
C. A reported issue that does not apply as described after validation.
D. A required remediation ticket.
11. Which action is an example of remediation?
A. Ignoring a confirmed vulnerability indefinitely.
B. Patching, upgrading, changing configuration, removing a vulnerable component, or restricting exposure.
C. Deleting all scan results.
D. Renaming the vulnerability.
12. What is a compensating control?
A. A guarantee that remediation is never needed.
B. A decorative document section.
C. A replacement for all vulnerability scanning.
D. A control or measure that reduces risk when the primary remediation is delayed or not immediately feasible.
13. Why is validation needed before closing a vulnerability?
A. It helps confirm that the weakness was actually corrected, mitigated, or appropriately dispositioned.
B. It replaces asset inventory.
C. It makes all future scans unnecessary.
D. It proves the system has no risk.
14. What is a POA&M used for conceptually?
A. Designing a user interface.
B. Tracking weaknesses, planned corrective actions, owners, milestones, and status.
C. Replacing security testing.
D. Avoiding remediation evidence.
15. What makes vulnerability evidence useful?
A. It is vague and disconnected from the system.
B. It is stored only in memory.
C. It is current, traceable, relevant, reviewable, and connected to findings, remediation, or risk decisions.
D. It has no owner.
16. Which statement best summarizes FedRAMP vulnerability management?
A. It is only a monthly report.
B. It is only the responsibility of compliance staff.
C. It guarantees perfect security.
D. It is an ongoing process that connects vulnerability discovery, prioritization, remediation, validation, reporting, evidence, and risk management.
Submit Quiz
Previous