Lesson 08 - Group 4: Vulnerability Analysis and Remediation

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/9

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:20 PM on 7/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

10 Terms

1
New cards
NVD
National Vulnerability Database; a vulnerability-information source listed in Lesson 8.
2
New cards
SCAP and CVE
Security Content Automation Protocol and Common Vulnerabilities and Exposures.
3
New cards
CVSS
Common Vulnerability Scoring System used to assign vulnerability-severity scores.
4
New cards
What CVSS severity ranges are shown in Lesson 8?
0.1 or higher is Low, 4.0 or higher is Medium, 7.0 or higher is High, and 9.0 or higher is Critical.
5
New cards
False positive
A scanner or assessment tool incorrectly reports that a vulnerability exists.
6
New cards
False negative
A real vulnerability goes undetected during a scan.
7
New cards
How should vulnerability-scan findings be validated?
Examine relevant logs and supporting evidence.
8
New cards
What factors should be considered when prioritizing vulnerabilities?
Classification, exposure factor, impact, environmental variables, and organizational risk tolerance.
9
New cards
What vulnerability-response options are listed?
Patching, cybersecurity insurance, segmentation, compensating controls, and approved exceptions or exemptions.
10
New cards
How should remediation be validated?
Re-scan, audit, verify the result, and report the outcom