CompTIA Security+ SY0-701 Vulnerability Management Practice Test

 

Topic 16 focuses on Vulnerability Management for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes automated probing and assessment used to identify known weaknesses and configuration problems?

  1. Vulnerability scanning
  2. Proprietary threat feed
  3. Dynamic application analysis
  4. Static application analysis

Correct Answer: A

 

Correct Answer

Answer A is correct because Vulnerability scanning means automated probing and assessment used to identify known weaknesses and configuration problems.

Incorrect Answers

Answer B is incorrect because Proprietary threat feed represents a different security function. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer C is incorrect because Dynamic application analysis would fit a different scenario. Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions.

Answer D is incorrect because Static application analysis addresses a different requirement. Static application analysis refers to inspection of application code or binaries without executing them.

 

Question 2

To find insecure coding patterns during development or review, which security approach should be selected?

  1. CVSS
  2. Rescanning
  3. Static application analysis
  4. Bug bounty program

Correct Answer: C

 

Correct Answer

Answer C is correct because Static application analysis means inspection of application code or binaries without executing them.

Incorrect Answers

Answer A is incorrect because CVSS would fit a different scenario. CVSS refers to a standardized scoring framework for describing vulnerability severity characteristics.

Answer B is incorrect because Rescanning addresses a different security requirement. Rescanning refers to performing another assessment after remediation.

Answer D is incorrect because Bug bounty program addresses a different requirement. Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports.

 

Question 3

Which term describes testing an application while it is running to observe behavior and identify exploitable conditions?

  1. False negative
  2. Dynamic application analysis
  3. Exception or exemption
  4. Rescanning

Correct Answer: B

 

Correct Answer

Answer B is correct because Dynamic application analysis means testing an application while it is running to observe behavior and identify exploitable conditions.

Incorrect Answers

Answer A is incorrect because False negative addresses a different requirement. False negative refers to a real vulnerability that an assessment fails to detect.

Answer C is incorrect because Exception or exemption would fit a different scenario. Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership.

Answer D is incorrect because Rescanning represents a different security function. Rescanning refers to performing another assessment after remediation.

 

Question 4

To identify supply-chain exposure in third-party software components, which security approach should be selected?

  1. Dark-web monitoring
  2. Static application analysis
  3. Package monitoring
  4. Bug bounty program

Correct Answer: C

 

Correct Answer

Answer C is correct because Package monitoring means tracking libraries and dependencies for known vulnerabilities and risky versions.

Incorrect Answers

Answer A is incorrect because Dark-web monitoring would fit a different scenario. Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity.

Answer B is incorrect because Static application analysis addresses a different security requirement. Static application analysis refers to inspection of application code or binaries without executing them.

Answer D is incorrect because Bug bounty program addresses a different requirement. Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports.

 

Question 5

Which term describes publicly available information used to identify threats, exposures, or attacker activity?

  1. Risk-based prioritization
  2. Open-source intelligence (OSINT)
  3. Compensating control
  4. CVE

Correct Answer: B

 

Correct Answer

Answer B is correct because Open-source intelligence (OSINT) means publicly available information used to identify threats, exposures, or attacker activity.

Incorrect Answers

Answer A is incorrect because Risk-based prioritization represents a different security function. Risk-based prioritization refers to ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context.

Answer C is incorrect because Compensating control addresses a different requirement. Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

Answer D is incorrect because CVE would fit a different scenario. CVE refers to a standardized identifier assigned to a publicly disclosed vulnerability.

 

Question 6

To obtain curated indicators and analysis not necessarily available publicly, which security approach should be selected?

  1. Compensating control
  2. Proprietary threat feed
  3. False positive
  4. Penetration testing

Correct Answer: B

 

Correct Answer

Answer B is correct because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider.

Incorrect Answers

Answer A is incorrect because Compensating control addresses a different requirement. Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

Answer C is incorrect because False positive addresses a different security requirement. False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Answer D is incorrect because Penetration testing would fit a different scenario. Penetration testing refers to authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused.

 

Question 7

Which industry or community group shares security intelligence among members?

  1. Bug bounty program
  2. Rescanning
  3. False negative
  4. Information-sharing organization

Correct Answer: D

 

Correct Answer

Answer D is correct because Information-sharing organization means an industry or community group that shares security intelligence among members.

Incorrect Answers

Answer A is incorrect because Bug bounty program addresses a different requirement. Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports.

Answer B is incorrect because Rescanning would fit a different scenario. Rescanning refers to performing another assessment after remediation.

Answer C is incorrect because False negative represents a different security function. False negative refers to a real vulnerability that an assessment fails to detect.

 

Question 8

To identify external evidence of compromise or targeting, which security approach should be selected?

  1. Dark-web monitoring
  2. Open-source intelligence (OSINT)
  3. Proprietary threat feed
  4. False negative

Correct Answer: A

 

Correct Answer

Answer A is correct because Dark-web monitoring means observation of hidden or criminal online sources for leaked credentials, data, or threat activity.

Incorrect Answers

Answer B is incorrect because Open-source intelligence (OSINT) addresses a different security requirement. Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity.

Answer C is incorrect because Proprietary threat feed addresses a different requirement. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer D is incorrect because False negative would fit a different scenario. False negative refers to a real vulnerability that an assessment fails to detect.

 

Question 9

Which term describes authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused?

  1. Compensating control
  2. Open-source intelligence (OSINT)
  3. Penetration testing
  4. Risk-based prioritization

Correct Answer: C

 

Correct Answer

Answer C is correct because Penetration testing means authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused.

Incorrect Answers

Answer A is incorrect because Compensating control addresses a different requirement. Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

Answer B is incorrect because Open-source intelligence (OSINT) would fit a different scenario. Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity.

Answer D is incorrect because Risk-based prioritization represents a different security function. Risk-based prioritization refers to ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context.

 

Question 10

To receive and remediate legitimate findings without encouraging uncontrolled disclosure, which security approach should be selected?

  1. Static application analysis
  2. Compensating control
  3. CVE
  4. Responsible disclosure program

Correct Answer: D

 

Correct Answer

Answer D is correct because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely.

Incorrect Answers

Answer A is incorrect because Static application analysis would fit a different scenario. Static application analysis refers to inspection of application code or binaries without executing them.

Answer B is incorrect because Compensating control addresses a different security requirement. Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

Answer C is incorrect because CVE addresses a different requirement. CVE refers to a standardized identifier assigned to a publicly disclosed vulnerability.

 

Question 11

Which responsible disclosure program offers rewards for qualifying vulnerability reports?

  1. Exception or exemption
  2. CVE
  3. Responsible disclosure program
  4. Bug bounty program

Correct Answer: D

 

Correct Answer

Answer D is correct because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports.

Incorrect Answers

Answer A is incorrect because Exception or exemption represents a different security function. Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership.

Answer B is incorrect because CVE would fit a different scenario. CVE refers to a standardized identifier assigned to a publicly disclosed vulnerability.

Answer C is incorrect because Responsible disclosure program addresses a different requirement. Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely.

 

Question 12

To avoid wasting remediation effort by confirming findings before action, which security approach should be selected?

  1. False positive
  2. Dark-web monitoring
  3. Compensating control
  4. Package monitoring

Correct Answer: A

 

Correct Answer

Answer A is correct because False positive means a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Incorrect Answers

Answer B is incorrect because Dark-web monitoring would fit a different scenario. Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity.

Answer C is incorrect because Compensating control addresses a different requirement. Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

Answer D is incorrect because Package monitoring addresses a different security requirement. Package monitoring refers to tracking libraries and dependencies for known vulnerabilities and risky versions.

 

Question 13

Which real vulnerability an assessment fails to detect?

  1. CVSS
  2. Open-source intelligence (OSINT)
  3. False negative
  4. Risk-based prioritization

Correct Answer: C

 

Correct Answer

Answer C is correct because False negative means a real vulnerability that an assessment fails to detect.

Incorrect Answers

Answer A is incorrect because CVSS would fit a different scenario. CVSS refers to a standardized scoring framework for describing vulnerability severity characteristics.

Answer B is incorrect because Open-source intelligence (OSINT) represents a different security function. Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity.

Answer D is incorrect because Risk-based prioritization addresses a different requirement. Risk-based prioritization refers to ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context.

 

Question 14

To support consistent severity assessment while still considering local business context, which security approach should be selected?

  1. Information-sharing organization
  2. False positive
  3. Exposure factor
  4. CVSS

Correct Answer: D

 

Correct Answer

Answer D is correct because CVSS means a standardized scoring framework for describing vulnerability severity characteristics.

Incorrect Answers

Answer A is incorrect because Information-sharing organization addresses a different requirement. Information-sharing organization refers to an industry or community group that shares security intelligence among members.

Answer B is incorrect because False positive would fit a different scenario. False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Answer C is incorrect because Exposure factor addresses a different security requirement. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

 

Question 15

Which standardized identifier is assigned to a publicly disclosed vulnerability?

  1. Dark-web monitoring
  2. CVE
  3. Proprietary threat feed
  4. Exception or exemption

Correct Answer: B

 

Correct Answer

Answer B is correct because CVE means a standardized identifier assigned to a publicly disclosed vulnerability.

Incorrect Answers

Answer A is incorrect because Dark-web monitoring would fit a different scenario. Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity.

Answer C is incorrect because Proprietary threat feed represents a different security function. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer D is incorrect because Exception or exemption addresses a different requirement. Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership.

 

Question 16

To quantify impact in risk analysis and prioritization, which security approach should be selected?

  1. Exposure factor
  2. Proprietary threat feed
  3. Vulnerability scanning
  4. False negative

Correct Answer: A

 

Correct Answer

Answer A is correct because Exposure factor means the estimated percentage of asset value lost if a specific risk event occurs.

Incorrect Answers

Answer B is incorrect because Proprietary threat feed would fit a different scenario. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer C is incorrect because Vulnerability scanning addresses a different requirement. Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems.

Answer D is incorrect because False negative addresses a different security requirement. False negative refers to a real vulnerability that an assessment fails to detect.

 

Question 17

Which term describes ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context?

  1. Risk-based prioritization
  2. Dynamic application analysis
  3. Package monitoring
  4. Exposure factor

Correct Answer: A

 

Correct Answer

Answer A is correct because Risk-based prioritization means ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context.

Incorrect Answers

Answer B is incorrect because Dynamic application analysis would fit a different scenario. Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions.

Answer C is incorrect because Package monitoring addresses a different requirement. Package monitoring refers to tracking libraries and dependencies for known vulnerabilities and risky versions.

Answer D is incorrect because Exposure factor represents a different security function. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

 

Question 18

To lower exposure until a permanent fix is available, which security approach should be selected?

  1. Exposure factor
  2. Exception or exemption
  3. False negative
  4. Compensating control

Correct Answer: D

 

Correct Answer

Answer D is correct because Compensating control means an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

Incorrect Answers

Answer A is incorrect because Exposure factor addresses a different security requirement. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

Answer B is incorrect because Exception or exemption would fit a different scenario. Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership.

Answer C is incorrect because False negative addresses a different requirement. False negative refers to a real vulnerability that an assessment fails to detect.

 

Question 19

Which term describes formally approved deviation from a security requirement under defined conditions and ownership?

  1. Exception or exemption
  2. Responsible disclosure program
  3. False positive
  4. Bug bounty program

Correct Answer: A

 

Correct Answer

Answer A is correct because Exception or exemption means formally approved deviation from a security requirement under defined conditions and ownership.

Incorrect Answers

Answer B is incorrect because Responsible disclosure program represents a different security function. Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely.

Answer C is incorrect because False positive addresses a different requirement. False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Answer D is incorrect because Bug bounty program would fit a different scenario. Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports.

 

Question 20

To verify that a vulnerability was actually removed and did not remain exposed, which security approach should be selected?

  1. Package monitoring
  2. Open-source intelligence (OSINT)
  3. Rescanning
  4. Information-sharing organization

Correct Answer: C

 

Correct Answer

Answer C is correct because Rescanning means performing another assessment after remediation. In practical terms, it is used to verify that a vulnerability was actually removed and did not remain exposed.

Incorrect Answers

Answer A is incorrect because Package monitoring addresses a different requirement. Package monitoring refers to tracking libraries and dependencies for known vulnerabilities and risky versions.

Answer B is incorrect because Open-source intelligence (OSINT) addresses a different security requirement. Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity.

Answer D is incorrect because Information-sharing organization would fit a different scenario. Information-sharing organization refers to an industry or community group that shares security intelligence among members.

 

Question 21

To discover candidate vulnerabilities across systems and applications, which security approach should be selected?

  1. Dynamic application analysis
  2. Vulnerability scanning
  3. Exposure factor
  4. Proprietary threat feed

Correct Answer: B

 

Correct Answer

Answer B is correct because Vulnerability scanning means automated probing and assessment used to identify known weaknesses and configuration problems.

Incorrect Answers

Answer A is incorrect because Dynamic application analysis represents a different security function. Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions.

Answer C is incorrect because Exposure factor addresses a different security requirement. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

Answer D is incorrect because Proprietary threat feed would fit a different scenario. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

 

Question 22

Which term describes inspection of application code or binaries without executing them?

  1. Proprietary threat feed
  2. CVSS
  3. Static application analysis
  4. Vulnerability scanning

Correct Answer: C

 

Correct Answer

Answer C is correct because Static application analysis means inspection of application code or binaries without executing them.

Incorrect Answers

Answer A is incorrect because Proprietary threat feed represents a different security function. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer B is incorrect because CVSS addresses a different requirement. CVSS refers to a standardized scoring framework for describing vulnerability severity characteristics.

Answer D is incorrect because Vulnerability scanning addresses a different security requirement. Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems.

 

Question 23

To find runtime vulnerabilities from an external or black-box perspective, which security approach should be selected?

  1. False negative
  2. Dynamic application analysis
  3. Exception or exemption
  4. Compensating control

Correct Answer: B

 

Correct Answer

Answer B is correct because Dynamic application analysis means testing an application while it is running to observe behavior and identify exploitable conditions.

Incorrect Answers

Answer A is incorrect because False negative would fit a different scenario. False negative refers to a real vulnerability that an assessment fails to detect.

Answer C is incorrect because Exception or exemption addresses a different security requirement. Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership.

Answer D is incorrect because Compensating control represents a different security function. Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

 

Question 24

Which term describes tracking libraries and dependencies for known vulnerabilities and risky versions?

  1. Proprietary threat feed
  2. False positive
  3. Package monitoring
  4. Static application analysis

Correct Answer: C

 

Correct Answer

Answer C is correct because Package monitoring means tracking libraries and dependencies for known vulnerabilities and risky versions.

Incorrect Answers

Answer A is incorrect because Proprietary threat feed addresses a different security requirement. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer B is incorrect because False positive addresses a different requirement. False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Answer D is incorrect because Static application analysis represents a different security function. Static application analysis refers to inspection of application code or binaries without executing them.

 

Question 25

To augment vulnerability and threat analysis with external public sources, which security approach should be selected?

  1. Bug bounty program
  2. Proprietary threat feed
  3. Open-source intelligence (OSINT)
  4. Responsible disclosure program

Correct Answer: C

 

Correct Answer

Answer C is correct because Open-source intelligence (OSINT) means publicly available information used to identify threats, exposures, or attacker activity.

Incorrect Answers

Answer A is incorrect because Bug bounty program addresses a different security requirement. Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports.

Answer B is incorrect because Proprietary threat feed would fit a different scenario. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer D is incorrect because Responsible disclosure program represents a different security function. Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely.

 

Question 26

Which term describes commercial or private threat intelligence supplied by a vendor or specialized provider?

  1. Dynamic application analysis
  2. Proprietary threat feed
  3. False negative
  4. Bug bounty program

Correct Answer: B

 

Correct Answer

Answer B is correct because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider.

Incorrect Answers

Answer A is incorrect because Dynamic application analysis addresses a different security requirement. Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions.

Answer C is incorrect because False negative represents a different security function. False negative refers to a real vulnerability that an assessment fails to detect.

Answer D is incorrect because Bug bounty program addresses a different requirement. Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports.

 

Question 27

To improve collective awareness of threats affecting similar organizations, which security approach should be selected?

  1. Information-sharing organization
  2. Exposure factor
  3. Static application analysis
  4. Dark-web monitoring

Correct Answer: A

 

Correct Answer

Answer A is correct because Information-sharing organization means an industry or community group that shares security intelligence among members.

Incorrect Answers

Answer B is incorrect because Exposure factor addresses a different security requirement. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

Answer C is incorrect because Static application analysis would fit a different scenario. Static application analysis refers to inspection of application code or binaries without executing them.

Answer D is incorrect because Dark-web monitoring represents a different security function. Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity.

 

Question 28

Which term describes observation of hidden or criminal online sources for leaked credentials, data, or threat activity?

  1. False positive
  2. Vulnerability scanning
  3. Responsible disclosure program
  4. Dark-web monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because Dark-web monitoring means observation of hidden or criminal online sources for leaked credentials, data, or threat activity.

Incorrect Answers

Answer A is incorrect because False positive addresses a different requirement. False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Answer B is incorrect because Vulnerability scanning addresses a different security requirement. Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems.

Answer C is incorrect because Responsible disclosure program represents a different security function. Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely.

 

Question 29

To validate real-world impact beyond a scanner finding, which security approach should be selected?

  1. Responsible disclosure program
  2. Exposure factor
  3. False positive
  4. Penetration testing

Correct Answer: D

 

Correct Answer

Answer D is correct because Penetration testing means authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused.

Incorrect Answers

Answer A is incorrect because Responsible disclosure program addresses a different security requirement. Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely.

Answer B is incorrect because Exposure factor would fit a different scenario. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

Answer C is incorrect because False positive represents a different security function. False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

 

Question 30

What is a defined process for external researchers to report security vulnerabilities safely?

  1. Vulnerability scanning
  2. Responsible disclosure program
  3. CVE
  4. Exposure factor

Correct Answer: B

 

Correct Answer

Answer B is correct because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely.

Incorrect Answers

Answer A is incorrect because Vulnerability scanning addresses a different security requirement. Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems.

Answer C is incorrect because CVE represents a different security function. CVE refers to a standardized identifier assigned to a publicly disclosed vulnerability.

Answer D is incorrect because Exposure factor addresses a different requirement. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

 

Question 31

To incentivize independent security research under defined rules, which security approach should be selected?

  1. Responsible disclosure program
  2. Bug bounty program
  3. Exception or exemption
  4. Vulnerability scanning

Correct Answer: B

 

Correct Answer

Answer B is correct because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports.

Incorrect Answers

Answer A is incorrect because Responsible disclosure program addresses a different security requirement. Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely.

Answer C is incorrect because Exception or exemption would fit a different scenario. Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership.

Answer D is incorrect because Vulnerability scanning represents a different security function. Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems.

 

Question 32

Which reported vulnerability or alert appears valid to the tool but is not actually present or exploitable in the assessed context?

  1. False positive
  2. Penetration testing
  3. Risk-based prioritization
  4. Dynamic application analysis

Correct Answer: A

 

Correct Answer

Answer A is correct because False positive means a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Incorrect Answers

Answer B is incorrect because Penetration testing addresses a different requirement. Penetration testing refers to authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused.

Answer C is incorrect because Risk-based prioritization addresses a different security requirement. Risk-based prioritization refers to ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context.

Answer D is incorrect because Dynamic application analysis represents a different security function. Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions.

 

Question 33

To recognize that absence of a scanner finding does not prove absence of risk, which security approach should be selected?

  1. False negative
  2. False positive
  3. Information-sharing organization
  4. Open-source intelligence (OSINT)

Correct Answer: A

 

Correct Answer

Answer A is correct because False negative means a real vulnerability that an assessment fails to detect.

Incorrect Answers

Answer B is incorrect because False positive would fit a different scenario. False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.

Answer C is incorrect because Information-sharing organization represents a different security function. Information-sharing organization refers to an industry or community group that shares security intelligence among members.

Answer D is incorrect because Open-source intelligence (OSINT) addresses a different security requirement. Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity.

 

Question 34

What is a standardized scoring framework for describing vulnerability severity characteristics?

  1. Proprietary threat feed
  2. Dynamic application analysis
  3. CVSS
  4. Exposure factor

Correct Answer: C

 

Correct Answer

Answer C is correct because CVSS means a standardized scoring framework for describing vulnerability severity characteristics.

Incorrect Answers

Answer A is incorrect because Proprietary threat feed represents a different security function. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer B is incorrect because Dynamic application analysis addresses a different security requirement. Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions.

Answer D is incorrect because Exposure factor addresses a different requirement. Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs.

 

Question 35

To reference the same known vulnerability consistently across tools and advisories, which security approach should be selected?

  1. Rescanning
  2. Exception or exemption
  3. Proprietary threat feed
  4. CVE

Correct Answer: D

 

Correct Answer

Answer D is correct because CVE means a standardized identifier assigned to a publicly disclosed vulnerability.

Incorrect Answers

Answer A is incorrect because Rescanning represents a different security function. Rescanning refers to performing another assessment after remediation.

Answer B is incorrect because Exception or exemption would fit a different scenario. Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership.

Answer C is incorrect because Proprietary threat feed addresses a different security requirement. Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider.

img