Week 6 - Vulnerability Management and Security Assessment

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/55

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering key definitions, tools, scanning types, and distinctions from Unit 6 Vulnerability Management and Security Assessment.

Last updated 11:55 PM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

56 Terms

1
New cards
Vulnerability
A weakness that a threat could exploit.
2
New cards
Threat
A person, event, or condition capable of causing harm.
3
New cards
Risk
The potential harm that could result if a threat exploits a vulnerability.
4
New cards
Control (Countermeasure)
A safeguard used to reduce the likelihood or impact of a security risk.
5
New cards
Vulnerability Management
The continuous process of identifying, evaluating, prioritizing, fixing, and verifying security weaknesses.
6
New cards
Vulnerability Management Cycle
Identify assets → find vulnerabilities → evaluate and prioritize them → remediate or mitigate → verify the fix → repeat.
7
New cards
Asset Inventory
An accurate list of systems, software, owners, locations, and other properties needed to manage security.
8
New cards
Why does vulnerability management start with asset inventory?
You cannot scan, patch, monitor, or assign responsibility for a system you do not know exists.
9
New cards
What should an asset inventory include?
System purpose, owner, hardware, operating system, network information, installed software, exposure, data sensitivity, and lifecycle information.
10
New cards
Vulnerability Assessment
A systematic process for identifying and evaluating weaknesses in systems or applications.
11
New cards
Vulnerability Scan
Automated testing that looks for known vulnerabilities, missing patches, unsafe configurations, or other indicators of weakness.
12
New cards
Penetration Testing
An authorized and scoped security test that actively attempts to exploit weaknesses to demonstrate real-world impact.
13
New cards
Internal Scan
A vulnerability scan performed from inside the organization or trusted network.
14
New cards
External Scan
A vulnerability scan performed from outside the organization to identify internet-exposed systems, services, and weaknesses.
15
New cards
Internal vs. External Scan
An internal scan shows what may be reachable after someone gets inside the network. An external scan shows what an internet-based attacker can see.
16
New cards
Credentialed Scan
A vulnerability scan performed with authorized login access, allowing deeper inspection of installed software, patches, and configuration.
17
New cards
Uncredentialed Scan
A vulnerability scan performed without host credentials that relies mainly on what can be observed from the network.
18
New cards
Credentialed vs. Uncredentialed Scan
A credentialed scan can inspect the system internally. An uncredentialed scan sees mainly the externally observable attack surface.
19
New cards
Why can a credentialed scan find more vulnerabilities?
It can directly inspect installed software, patch levels, and configuration instead of inferring them only from network responses.
20
New cards
CVE (Common Vulnerabilities and Exposures)
A standardized identifier used to refer to a specific publicly disclosed vulnerability.
21
New cards
CVE format
CVE-Year-Identifier. Example: CVE-2021-44228.
22
New cards
Is a CVE malware?
No. A CVE is an identifier for a known vulnerability.
23
New cards
NVD (National Vulnerability Database)
NIST's vulnerability database that adds standardized details, scoring information, affected products, weaknesses, and references to CVE records.
24
New cards
CVSS (Common Vulnerability Scoring System)
A scoring system used to communicate the technical severity of a vulnerability, typically on a scale from 0 to 10.
25
New cards
KEV (Known Exploited Vulnerabilities)
CISA's catalog of vulnerabilities with evidence of real-world exploitation, used as an important prioritization signal.
26
New cards
CVE vs. CVSS
CVE identifies the vulnerability. CVSS describes its technical severity.
27
New cards
CVE vs. NVD
CVE provides the standardized vulnerability identifier. The NVD adds analysis and additional vulnerability information.
28
New cards
CVSS vs. KEV
CVSS measures technical severity. KEV tells defenders that the vulnerability is known to be actively exploited.
29
New cards
False Positive
A vulnerability or security issue reported by a tool that is not actually present.
30
New cards
False Negative
A real vulnerability that an assessment or scanner fails to detect.
31
New cards
False Positive vs. False Negative
A false positive reports a problem that is not real. A false negative misses a real problem.
32
New cards
Remediation
Removing or correcting the underlying vulnerability, such as installing the required patch.
33
New cards
Mitigation
Reducing the risk around a vulnerability without fully removing the underlying weakness.
34
New cards
Compensating Control
An alternative safeguard used when the preferred security control cannot be implemented.
35
New cards
Risk Acceptance
A documented decision by authorized leadership to tolerate a known remaining risk.
36
New cards
Risk Transfer
Shifting some financial or operational impact of a risk to another party, such as through insurance or a contract.
37
New cards
Risk Avoidance
Removing the risky activity entirely so the associated risk no longer applies.
38
New cards
Remediation vs. Mitigation
Remediation removes the weakness. Mitigation reduces the risk while the weakness still exists.
39
New cards
Compensating Control vs. Remediation
A compensating control reduces risk when the preferred fix cannot be used. Remediation actually removes or corrects the weakness.
40
New cards
Rescan
A follow-up scan performed after remediation or mitigation to verify whether the vulnerability is gone or sufficiently controlled.
41
New cards
Why is a rescan important?
A closed ticket does not prove the vulnerability was fixed. A rescan or other validation confirms the actual security condition changed.
42
New cards
What proves remediation worked?
A rescan or other validation showing that the vulnerable condition is no longer present.
43
New cards
Technical Severity
The inherent technical seriousness of a vulnerability, often represented using CVSS.
44
New cards
Organizational Risk
The actual risk the vulnerability creates for a specific organization after considering business context.
45
New cards
Why is CVSS not the same as organizational risk?
CVSS describes technical severity, but real priority also depends on exposure, active exploitation, asset value, data sensitivity, existing controls, and business impact.
46
New cards
What factors should affect vulnerability priority?
Technical severity, internet exposure, active exploitation, asset criticality, data sensitivity, existing controls, and potential business impact.
47
New cards
Scan vs. Penetration Test
A vulnerability scan identifies likely weaknesses automatically. A penetration test actively attempts to demonstrate whether weaknesses can be exploited and what impact they could cause.
48
New cards
Threat vs. Vulnerability
A threat is a potential source of harm. A vulnerability is a weakness that the threat could exploit.
49
New cards
Vulnerability vs. Risk
A vulnerability is the weakness itself. Risk is the potential harm created if that weakness is exploited.
50
New cards
Threat vs. Risk
A threat is what could cause harm. Risk describes the likelihood and impact of that harm affecting the organization.
51
New cards
Nessus
A vulnerability scanner used to discover hosts and identify known vulnerabilities or configuration weaknesses.
52
New cards
What does a vulnerability scanner actually prove?
It reports possible or likely weaknesses. A scan result does not automatically prove that the weakness can be successfully exploited.
53
New cards
An internet-facing payroll server and an isolated lab PC have the same critical vulnerability. Which should be prioritized first?
The payroll server, because its exposure and business importance create greater organizational risk.
54
New cards
A medical device cannot be patched for 60 days. What is a reasonable interim response?
Segment the device, restrict allowed communication, increase monitoring, assign responsibility and a deadline, then patch and verify when possible.
55
New cards
A scanner reports software as vulnerable, but the vendor already backported the security fix. What is this?
A false positive.
56
New cards
A custom vulnerable application is not detected by the scanner. What is this?
A false negative.