Vulnerability Management

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/157

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:59 AM on 9/19/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

158 Terms

1
New cards

What is a Vulnerability?

A weakness, deficiency, or flaw in an information system that can be exploited by a threat

2
New cards

What is Vulnerability Management?

The process of identifying, analyzing, prioritizing, reporting, and remediating vulnerabilities

3
New cards

What is a Zero-Day Vulnerability?

A vulnerability that has been identified but not yet publicly disclosed

4
New cards

What is a Zero-Day Exploit?

An exploit for which no patch or fix is available

5
New cards

What does CWE stand for?

Common Weakness Enumeration

6
New cards

What is CWE?

A list of common software weaknesses that can lead to vulnerabilities

7
New cards

What does CVE stand for?

Common Vulnerabilities and Exposures

8
New cards

What is CVE?

A list of publicly disclosed cybersecurity vulnerabilities and exposures

9
New cards

What is the primary goal of Vulnerability Management?

Reduce risk by identifying and mitigating vulnerabilities before exploitation

10
New cards

What is the difference between Vulnerability Management and Patch Management?

Vulnerability Management identifies weaknesses while Patch Management applies updates and fixes

11
New cards

Are Vulnerability Management and Patch Management the same?

No

12
New cards

Who is accountable for vulnerabilities impacting an asset?

The Asset Owner

13
New cards

What is the risk formula for a client?

Impact × Likelihood

14
New cards

What are examples of impact caused by vulnerabilities?

Data loss, encryption, service disruption, and sensitive data exposure

15
New cards

What increases the likelihood of exploitation?

Exposure to the internet and accessible vulnerable systems

16
New cards

What are the five stages of the Vulnerability Management Lifecycle?

Identification, Analysis and Prioritization, Communication and Remediation, Reporting, Dashboarding and Continuous Improvement

17
New cards

What stage occurs before the VM Lifecycle begins?

Preparation

18
New cards

What happens during Preparation?

Governance, onboarding, scanning improvements, and training

19
New cards

What happens during Identification?

Continuous monitoring and vulnerability discovery

20
New cards

What happens during Analysis and Prioritization?

Risk-based prioritization using severity, threat intelligence, and asset context

21
New cards

What happens during Communication and Remediation?

Asset owner notification and remediation support

22
New cards

What happens during Reporting?

Reporting on vulnerabilities, risks, trends, and recommendations

23
New cards

What happens during Dashboarding and Continuous Improvement?

Measuring KPIs and improving VM capabilities

24
New cards

What does CVSS stand for?

Common Vulnerability Scoring System

25
New cards

What is CVSS used for?

Measuring vulnerability severity and assisting prioritization

26
New cards

What are common sources for vulnerability identification?

Scanning, threat intelligence, and vendor notifications

27
New cards

What are the four major functions of a Vulnerability Management Program?

Discovery, Prioritization, Action, Reporting

28
New cards

What does Discovery accomplish?

Identifies vulnerabilities through scanners and security tools

29
New cards

What does Prioritization accomplish?

Ranks vulnerabilities based on risk and severity

30
New cards

What does Action accomplish?

Applies fixes and mitigations

31
New cards

What does Reporting accomplish?

Provides visibility into trends and risks

32
New cards

What makes an effective Vulnerability Management Program?

Continuous scanning, remediation, automation, reporting, and risk visibility

33
New cards

Why is automation important in VM?

Reduces manual workload and improves efficiency

34
New cards

Why is Vulnerability Management essential for compliance?

It provides visibility into risk and remediation efforts

35
New cards

What are the four Vulnerability Management maturity levels?

Basic, Emerging, Foundational, Mature

36
New cards

Which VM maturity level uses ad-hoc unauthenticated scans?

Basic

37
New cards

Which VM maturity level has little or no formal vulnerability management?

Basic

38
New cards

Which VM maturity level performs periodic authenticated scanning?

Emerging

39
New cards

Which VM maturity level lacks a governance model but performs partial vulnerability management?

Emerging

40
New cards

Which VM maturity level has a defined VM program and governance model?

Foundational

41
New cards

Which VM maturity level includes clear roles and responsibilities?

Foundational

42
New cards

Which VM maturity level integrates with CMDB and other enterprise systems?

Mature

43
New cards

What does CMDB stand for?

Configuration Management Database

44
New cards

Which VM maturity level provides customized dashboards and reporting?

Mature

45
New cards

Which VM maturity level manages End of Service and End of Life assets?

Mature

46
New cards

What does EOS stand for?

End of Service

47
New cards

What does EOL stand for?

End of Life

48
New cards

What are the three ways vulnerabilities can be treated?

Remediation, False Positive, Exception

49
New cards

What is Remediation?

Fixing a vulnerability through patching, isolation, or removal

50
New cards

What is a False Positive?

A vulnerability finding that is not actually valid and may be whitelisted

51
New cards

What is an Exception?

A temporary acceptance of risk when remediation cannot be completed on time

52
New cards

How are vulnerabilities communicated to Asset Owners?

User Dashboard or Manual Alerting

53
New cards

What is the User Dashboard model?

A self-service vulnerability management approach

54
New cards

When is Manual Alerting typically used?

Emergency vulnerabilities

55
New cards

Who communicates emergency vulnerabilities?

The TVM Team

56
New cards

What does TVM stand for?

Threat and Vulnerability Management

57
New cards

Who remains accountable for all vulnerabilities regardless of remediation ownership?

The Asset Owner

58
New cards

Who is responsible for executing remediation tasks?

The Supporting Team

59
New cards

Which team typically handles Business Applications?

Application Team

60
New cards

Which team typically handles Operating System vulnerabilities?

Infrastructure Team

61
New cards

Which team usually manages Standard Software vulnerabilities?

Infrastructure Team

62
New cards

Which team typically manages Database and Library vulnerabilities?

Application Team

63
New cards

Which team commonly handles SSL and TLS related vulnerabilities?

Application Team

64
New cards

What does SSL stand for?

Secure Sockets Layer

65
New cards

What does TLS stand for?

Transport Layer Security

66
New cards

Which team commonly handles Microsoft Security Updates?

Infrastructure Team

67
New cards

Which team commonly handles VMware vulnerabilities?

Infrastructure Team

68
New cards

Which team commonly handles Apache vulnerabilities?

Application Team

69
New cards

Which team commonly handles .NET and Java vulnerabilities?

Application Team

70
New cards

Which team commonly handles Chrome and Firefox vulnerabilities?

Application Team

71
New cards

Which team commonly handles 7-Zip vulnerabilities?

Infrastructure Team

72
New cards

What is the key principle regarding accountability and responsibility?

Asset Owner is Accountable, Supporting Team is Responsible

73
New cards

Which VM Lifecycle phase includes reviewing non-compliant remediation?

Reporting

74
New cards

Which VM Lifecycle phase includes notifying Asset Owners?

Communication and Remediation

75
New cards

Which VM Lifecycle phase focuses on risk-based prioritization?

Analysis and Prioritization

76
New cards

Which VM Lifecycle phase focuses on vulnerability discovery?

Identification

77
New cards

Which VM Lifecycle phase focuses on KPIs and metrics?

Dashboarding and Continuous Improvement

78
New cards

What is the purpose of Strategic Reporting?

Provide vulnerability trends, risks, impacts, and recommendations

79
New cards

What should Vulnerability Management continuously monitor?

Systems, applications, and assets

80
New cards

Why is Governance important in Vulnerability Management?

It defines accountability, processes, and responsibilities

81
New cards

What is the purpose of onboarding new assets into the VM process?

Ensure continuous vulnerability coverage

82
New cards

What information is commonly included in a vulnerability report?

Impacted assets, trends, risks, and recommendations

83
New cards

What is the ultimate objective of Vulnerability Management?

Reduce organizational risk by identifying and addressing vulnerabilities before attackers can exploit them

84
New cards

What does IVM stand for?

Infrastructure Vulnerability Management

85
New cards

What does CTEM stand for?

Continuous Threat Exposure Management

86
New cards

What does RCE stand for?

Remote Code Execution

87
New cards

What does MFA stand for?

Multi-Factor Authentication

88
New cards

What does GRC stand for?

Governance, Risk Management, and Compliance

89
New cards

What is an Exploit?

A method or code used to take advantage of a vulnerability

90
New cards

What is a Patch?

A software update used to fix vulnerabilities or bugs

91
New cards

What does KEV stand for?

Known Exploited Vulnerabilities

92
New cards

What is CISA KEV?

A catalog of vulnerabilities actively exploited in the wild

93
New cards

What is a Threat in the vulnerability analogy?

The burglar

94
New cards

What is a Vulnerability in the analogy?

An unlocked window due to broken locks

95
New cards

What is an Exploit in the analogy?

A burglar climbing through the unlocked window

96
New cards

What is Risk in the analogy?

Loss of valuables

97
New cards

What is a Misconfiguration Vulnerability?

A vulnerability caused by insecure settings

98
New cards

What are examples of Misconfigurations?

Open ports, weak SSL/TLS, disabled firewall

99
New cards

What are Weak Credentials?

Default passwords, weak passwords, and lack of MFA

100
New cards

What is a Missing Patch Vulnerability?

Software lacking security updates