Loading course title...
Loading assessment title...
Connecting to LMS...
Progress: in progress
Assessment
1. What best describes vulnerability management?
A. A one-time scan report
B. A replacement for incident response
C. An ongoing lifecycle for finding, prioritizing, fixing, and verifying weaknesses
D. A compliance task with no operational impact
2. Why is asset inventory foundational to vulnerability management?
A. Findings need assets, owners, business context, and exposure information
B. Inventory replaces remediation
C. Inventory proves there are no vulnerabilities
D. Inventory removes the need for scanning
3. Which discovery method usually provides richer local evidence when credentials are working?
A. Guessing from asset names
B. Reading an old spreadsheet
C. Ignoring endpoints
D. Authenticated scanning
4. What is a false positive?
A. A finding that is exploited in the wild
B. A reported vulnerability that does not actually apply
C. A vulnerability with no owner
D. A finding that was patched successfully
5. Why is CVSS useful but incomplete for prioritization?
A. It includes every local business detail automatically
B. It replaces asset ownership
C. It provides severity language but not full local risk context
D. It proves exploitability in production
6. What is mitigation in vulnerability management?
A. Deleting all findings without review
B. Marking every vulnerability as accepted risk
C. Ignoring systems until the next audit
D. Reducing risk when immediate remediation is not practical
7. What should delayed patching represent?
A. A visible risk decision with owner, rationale, controls, and review
B. An invisible backlog item
C. A reason to stop scanning
D. Proof that the vulnerability is not real
8. What should a good exception record include?
A. Only the word approved
B. Accepted risk, owner, compensating control, expiration date, and rationale
C. No review date
D. A deleted finding
9. Which metric helps identify whether remediation work is aging beyond expectations?
A. Desktop wallpaper count
B. Number of meeting invitations
C. Age of open vulnerabilities
D. Length of the asset hostname
10. What is the main goal of vulnerability management metrics?
A. Blame system owners
B. Create longer reports
C. Hide coverage gaps
D. Drive measurable risk reduction and process improvement
Submit Quiz
Previous