1/157
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a Vulnerability?
A weakness, deficiency, or flaw in an information system that can be exploited by a threat
What is Vulnerability Management?
The process of identifying, analyzing, prioritizing, reporting, and remediating vulnerabilities
What is a Zero-Day Vulnerability?
A vulnerability that has been identified but not yet publicly disclosed
What is a Zero-Day Exploit?
An exploit for which no patch or fix is available
What does CWE stand for?
Common Weakness Enumeration
What is CWE?
A list of common software weaknesses that can lead to vulnerabilities
What does CVE stand for?
Common Vulnerabilities and Exposures
What is CVE?
A list of publicly disclosed cybersecurity vulnerabilities and exposures
What is the primary goal of Vulnerability Management?
Reduce risk by identifying and mitigating vulnerabilities before exploitation
What is the difference between Vulnerability Management and Patch Management?
Vulnerability Management identifies weaknesses while Patch Management applies updates and fixes
Are Vulnerability Management and Patch Management the same?
No
Who is accountable for vulnerabilities impacting an asset?
The Asset Owner
What is the risk formula for a client?
Impact × Likelihood
What are examples of impact caused by vulnerabilities?
Data loss, encryption, service disruption, and sensitive data exposure
What increases the likelihood of exploitation?
Exposure to the internet and accessible vulnerable systems
What are the five stages of the Vulnerability Management Lifecycle?
Identification, Analysis and Prioritization, Communication and Remediation, Reporting, Dashboarding and Continuous Improvement
What stage occurs before the VM Lifecycle begins?
Preparation
What happens during Preparation?
Governance, onboarding, scanning improvements, and training
What happens during Identification?
Continuous monitoring and vulnerability discovery
What happens during Analysis and Prioritization?
Risk-based prioritization using severity, threat intelligence, and asset context
What happens during Communication and Remediation?
Asset owner notification and remediation support
What happens during Reporting?
Reporting on vulnerabilities, risks, trends, and recommendations
What happens during Dashboarding and Continuous Improvement?
Measuring KPIs and improving VM capabilities
What does CVSS stand for?
Common Vulnerability Scoring System
What is CVSS used for?
Measuring vulnerability severity and assisting prioritization
What are common sources for vulnerability identification?
Scanning, threat intelligence, and vendor notifications
What are the four major functions of a Vulnerability Management Program?
Discovery, Prioritization, Action, Reporting
What does Discovery accomplish?
Identifies vulnerabilities through scanners and security tools
What does Prioritization accomplish?
Ranks vulnerabilities based on risk and severity
What does Action accomplish?
Applies fixes and mitigations
What does Reporting accomplish?
Provides visibility into trends and risks
What makes an effective Vulnerability Management Program?
Continuous scanning, remediation, automation, reporting, and risk visibility
Why is automation important in VM?
Reduces manual workload and improves efficiency
Why is Vulnerability Management essential for compliance?
It provides visibility into risk and remediation efforts
What are the four Vulnerability Management maturity levels?
Basic, Emerging, Foundational, Mature
Which VM maturity level uses ad-hoc unauthenticated scans?
Basic
Which VM maturity level has little or no formal vulnerability management?
Basic
Which VM maturity level performs periodic authenticated scanning?
Emerging
Which VM maturity level lacks a governance model but performs partial vulnerability management?
Emerging
Which VM maturity level has a defined VM program and governance model?
Foundational
Which VM maturity level includes clear roles and responsibilities?
Foundational
Which VM maturity level integrates with CMDB and other enterprise systems?
Mature
What does CMDB stand for?
Configuration Management Database
Which VM maturity level provides customized dashboards and reporting?
Mature
Which VM maturity level manages End of Service and End of Life assets?
Mature
What does EOS stand for?
End of Service
What does EOL stand for?
End of Life
What are the three ways vulnerabilities can be treated?
Remediation, False Positive, Exception
What is Remediation?
Fixing a vulnerability through patching, isolation, or removal
What is a False Positive?
A vulnerability finding that is not actually valid and may be whitelisted
What is an Exception?
A temporary acceptance of risk when remediation cannot be completed on time
How are vulnerabilities communicated to Asset Owners?
User Dashboard or Manual Alerting
What is the User Dashboard model?
A self-service vulnerability management approach
When is Manual Alerting typically used?
Emergency vulnerabilities
Who communicates emergency vulnerabilities?
The TVM Team
What does TVM stand for?
Threat and Vulnerability Management
Who remains accountable for all vulnerabilities regardless of remediation ownership?
The Asset Owner
Who is responsible for executing remediation tasks?
The Supporting Team
Which team typically handles Business Applications?
Application Team
Which team typically handles Operating System vulnerabilities?
Infrastructure Team
Which team usually manages Standard Software vulnerabilities?
Infrastructure Team
Which team typically manages Database and Library vulnerabilities?
Application Team
Which team commonly handles SSL and TLS related vulnerabilities?
Application Team
What does SSL stand for?
Secure Sockets Layer
What does TLS stand for?
Transport Layer Security
Which team commonly handles Microsoft Security Updates?
Infrastructure Team
Which team commonly handles VMware vulnerabilities?
Infrastructure Team
Which team commonly handles Apache vulnerabilities?
Application Team
Which team commonly handles .NET and Java vulnerabilities?
Application Team
Which team commonly handles Chrome and Firefox vulnerabilities?
Application Team
Which team commonly handles 7-Zip vulnerabilities?
Infrastructure Team
What is the key principle regarding accountability and responsibility?
Asset Owner is Accountable, Supporting Team is Responsible
Which VM Lifecycle phase includes reviewing non-compliant remediation?
Reporting
Which VM Lifecycle phase includes notifying Asset Owners?
Communication and Remediation
Which VM Lifecycle phase focuses on risk-based prioritization?
Analysis and Prioritization
Which VM Lifecycle phase focuses on vulnerability discovery?
Identification
Which VM Lifecycle phase focuses on KPIs and metrics?
Dashboarding and Continuous Improvement
What is the purpose of Strategic Reporting?
Provide vulnerability trends, risks, impacts, and recommendations
What should Vulnerability Management continuously monitor?
Systems, applications, and assets
Why is Governance important in Vulnerability Management?
It defines accountability, processes, and responsibilities
What is the purpose of onboarding new assets into the VM process?
Ensure continuous vulnerability coverage
What information is commonly included in a vulnerability report?
Impacted assets, trends, risks, and recommendations
What is the ultimate objective of Vulnerability Management?
Reduce organizational risk by identifying and addressing vulnerabilities before attackers can exploit them
What does IVM stand for?
Infrastructure Vulnerability Management
What does CTEM stand for?
Continuous Threat Exposure Management
What does RCE stand for?
Remote Code Execution
What does MFA stand for?
Multi-Factor Authentication
What does GRC stand for?
Governance, Risk Management, and Compliance
What is an Exploit?
A method or code used to take advantage of a vulnerability
What is a Patch?
A software update used to fix vulnerabilities or bugs
What does KEV stand for?
Known Exploited Vulnerabilities
What is CISA KEV?
A catalog of vulnerabilities actively exploited in the wild
What is a Threat in the vulnerability analogy?
The burglar
What is a Vulnerability in the analogy?
An unlocked window due to broken locks
What is an Exploit in the analogy?
A burglar climbing through the unlocked window
What is Risk in the analogy?
Loss of valuables
What is a Misconfiguration Vulnerability?
A vulnerability caused by insecure settings
What are examples of Misconfigurations?
Open ports, weak SSL/TLS, disabled firewall
What are Weak Credentials?
Default passwords, weak passwords, and lack of MFA
What is a Missing Patch Vulnerability?
Software lacking security updates