Skip to content

Vulnerability Management Questions

Practice questions for Vulnerability Management topic in CompTIA CySA+. 27 questions covering this domain.

27 questions6 easy13 medium8 hard
Q1
hard

A penetration test report identifies that the organization's web application is vulnerable to insecure deserialization. The development team asks the ...

Q2
medium

A security team is scheduling vulnerability remediation and must patch a critical vulnerability on a production database server. Which vulnerability r...

Q3
easy

What does CVSS stand for, and what is its primary purpose?

Q4
medium

An analyst is reviewing the output of a web application scanner and finds a reflected cross-site scripting (XSS) vulnerability. Which mitigation contr...

Q5
medium

A vulnerability scanner reports a critical CVE on a server, but the organization's security team determines the vulnerable component is not reachable ...

Q6
easy

Which type of vulnerability scanning is performed without deploying an agent on the target system?

Q7
hard

A zero-day vulnerability is discovered in a widely used VPN appliance actively being exploited in the wild. No patch is available. Which response acti...

Q8
easy

What is the difference between credentialed and non-credentialed vulnerability scanning?

Q9
hard

A security analyst is reviewing assessment tool output from a Nessus scan of a DMZ segment. The report shows a critical finding titled 'SSL/TLS Use of...

Q10
hard

During a cloud infrastructure assessment, a security analyst discovers an AWS S3 bucket configured with public read access containing sensitive custom...

Q11
medium

Which factor should be given the highest weight when prioritizing vulnerability remediation across a large asset inventory?

Q12
medium

An analyst receives a web application scanner report showing a SQL injection vulnerability. Which mitigation should be recommended?

Q13
medium

An organization has 500 open vulnerabilities. The security team has limited resources and must prioritize remediation. A CVSS 7.2 vulnerability exists...

Q14
easy

Which type of vulnerability scan would be most appropriate for discovering vulnerabilities in a web application's business logic?

Q15
medium

An organization wants to perform vulnerability scanning of its cloud-hosted workloads in AWS. Which scanning approach provides the most comprehensive ...

Q16
hard

A newly released CVE has a CVSS base score of 6.5 but CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploi...

Q17
hard

During a vulnerability assessment of a critical infrastructure environment (ICS/OT), the security team proposes running an active credentialed vulnera...

Q18
medium

During a routine vulnerability scan, an analyst discovers that several workstations are running an end-of-life (EOL) operating system that no longer r...

Q19
easy

What does a CVSS base score of 9.8 indicate about a vulnerability?

Q20
medium

A security analyst is reviewing a vulnerability scan report and notices a finding marked as 'potential' rather than confirmed. What should the analyst...

Sign in to see all 27 questions

Create a free account to browse all questions — completely free during our launch phase.