Module 5: Vulnerability Remediation & Other Actions Flashcards

1
Q

Exception Management can be setup for how many types of Vulnerability Response?

A

All 4 types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which field allows you to select between Vulnerability Response or GRC?

A

Manage exceptions using

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What system property is set to true by default to enable Flow Designer for VR?

A

sn_vul.flow_designer_activation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

T/F: Exception rules are only valid with GRC Vulnerability Response

A

False - Exception Rules are only valid with non-GRC Vulnerability Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What enable you to automate the deferral process for vulnerable items (VIs)?

A

Exception rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Where are exceptions for IVR, AVR, and CVR stored?

A

[sn_vul_auto_exception_rule] table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

You can request an exception for the vulnerable items (VIs) that can’t be remediated or deferred immediately, by identifying the ________________, ________________, or ________________.

A

Impacted vulnerabilities
Configuration items (CIs)
Vulnerable items (VIs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Exceptions for Configuration Compliance are stored in which table?

A

[sn_vulc_auto_exception_rule]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is defined as a condition wherein the scanner reports that a vulnerability exists in the system, but in reality, there is no vulnerability?

A

False positive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are false positives available on?

A

Vulnerable items
Remediation tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

False positives are available for which vulnerability types?

A

Infrastructure
Application
Container

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What role is required to set something as a false positive?

A

Remediation Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What entails requesting, reviewing, approving, or rejecting exceptions to a vulnerable item (VI) or remediation task (RT) that cannot be remediated according to the policy?

A

Exception management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

______________________________ is when you acknowledge and agree to the consequences of not remediating a vulnerability.

A

Risk acceptance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

______________________ is when you resolve a vulnerability and mitigate its risk.

A

Remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Automatic exception approvals can be configured, based on:

A

Risk rating
Policy
Control objective

17
Q
A