Module 5 - Vulnerability Analysis Flashcards

1
Q

Vulnerability Assessment Concepts:

A system that is configured to stardard that I create an image of and use it to compare all other systems on the network.

A

Baseline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Vulnerability Assessment Solutions:

Find a way to get the job done with out costing additional money or extra steps.

A

Workarounds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Vulnerability Accessment Concepts:

An examination of the ability of a system or application, including current security procedures and controls, to withstand assault.

a. Active Assessment
b. Vulnerability Assessment
c. Network Assessment
d. Application Assessment

A

b. Vulnerability Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vulnerability Scoring Systems:

  • Is a publicly available and free to use list of dictionary of starndardized identifiers for common software vulnerabilities and exposures.
  • A basis for evaluation among services, tools, and databases.
    a. CVE (Common Vulnerabilities and Exposures)
    b. CVAS (Common Vulnerability Assessment Solutions)
    c. CVAT (Common Vulnerability Assessment Tools)
A

a. CVE (Common Vulnerabilities and Exposures)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Vulnerability Assessment Tools:

Lets administrators scan local and remote systems for missing security updates as well as common security misconfigurations.

a. Qualys FreeScan
b. Nikto
c. SAINT
d. MBSA (Microsoft Baseline Security Analyzer)

A

d. MBSA (Microsoft Baseline Security Analyzer)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Vulnerability Scoring Systems:

All of the following are severity levels of CVSS v3.0 except: (Choose 2)

a. Low
b. High
c. Critical
d. None
e. Medium
f. Extreme
g. Warning

A

f. Extreme
g. Warning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Vulnerability Scoring Systems:

What are the CVSS v2.0 Severity Level:

a. Critical
b. High
c. Low
d. None
e. Medium

A

b. High
c. Low
e. Medium

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Vulnerability Scoring Systems:

CVSS v2.0, what is the Base Score for the Medium severity level?

a. 0.0-3.9
b. 7.0-10
c. 4.0-6.9

A

c. 4.0-6.9

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Vulnerability Scoring Systems:

CVSS v3.0, What is the Base Score for the High severity level.

a. 9.0-10
b. 0.0
c. 4.0-6.9
d. 7.0-8.9
e. 0.1-3.9

A

d. 7.0-8.9

How well did you know this?
1
Not at all
2
3
4
5
Perfectly