wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Chapter 6: Designing a Vulnerability Management Program

Total questions: 20

Worksheet time: 20mins

Name
Class
Date
1.

What federal law requires the use of vulnerability scanning on information systems operated by federal government agencies?

a)
  1. HIPAA

b)
  1. GLBA

c)
  1. FISMA

d)
  1. FERPA

2.

Which one of the following industry standards describes a standard approach for setting up an information security management system?

a)
  1. OWASP

b)
  1. CIS

c)
  1. ISO 27002

d)
  1. ISO 27001

3.

What tool can administrators use to help identify the systems present on a network prior to conducting vulnerability scans?

a)
  1. Asset inventory

b)
  1. Web application assessment

c)
  1. Router

d)
  1. DLP

4.

Tonya is configuring vulnerability scans for a system that is subject to the PCI DSS compliance standard. What is the minimum frequency with which she must conduct scans?

a)
  1. Daily

b)
  1. Weekly

c)
  1. Monthly

d)
  1. Quarterly

5.

Which one of the following is not an example of a vulnerability scanning tool?

a)
  1. Nikto

b)
  1. Snort

c)
  1. Nessus

d)
  1. OpenVAS

6.

Bethany is the vulnerability management specialist for a large retail organization. She completed her last PCI DSS compliance scan in March. In April, the organization upgraded their point-of-sale system, and Bethany is preparing to conduct new scans. When must she complete the new scan?

a)
  1. Immediately.

b)
  1. June.

c)
  1. December.

d)
  1. No scans are required.

7.

Renee is configuring her vulnerability management solution to perform credentialed scans of servers on her network. What type of account should she provide to the scanner?

a)
  1. Domain administrator

b)
  1. Local administrator

c)
  1. Root

d)
  1. Read-only

8.

Jason is writing a report about a potential security vulnerability in a software product and wishes to use standardized product names to ensure that other security analysts understand the report. Which SCAP component can Jason turn to for assistance?

a)
  1. CVSS

b)
  1. CVE

c)
  1. CPE

d)
  1. OVAL

9.

Bill would like to run an internal vulnerability scan on a system for PCI DSS compliance purposes. Who is authorized to complete one of these scans?

a)
  1. Any employee of the organization

b)
  1. An approved scanning vendor

c)
  1. A PCI DSS service provider

d)
  1. Any qualified individual

10.

Which type of organization is the most likely to face a regulatory requirement to conduct vulnerability scans?

a)
  1. Bank

b)
  1. Hospital

c)
  1. Government agency

d)
  1. Doctor's office

11.

Which one of the following organizations focuses on providing tools and advice for secure web application development?

a)
  1. OWASP

b)
  1. CIS

c)
  1. NIST

d)
  1. Microsoft

12.

What term describes an organization's willingness to tolerate risk in their computing environment?

a)
  1. Risk landscape

b)
  1. Risk appetite

c)
  1. Risk level

d)
  1. Risk adaptation

13.

Which one of the following factors is least likely to impact vulnerability scanning schedules?

a)
  1. Regulatory requirements

b)
  1. Technical constraints

c)
  1. Business constraints

d)
  1. Staff availability

14.

Barry placed all of his organization's credit card processing systems on an isolated network dedicated to card processing. He has implemented appropriate segmentation controls to limit the scope of PCI DSS to those systems through the use of VLANs and firewalls. When Barry goes to conduct vulnerability scans for PCI DSS compliance purposes, what systems must he scan?

a)
  1. Customer systems

b)
  1. Systems on the isolated network

c)
  1. Systems on the general enterprise network

15.

Ryan is planning to conduct a vulnerability scan of a business-critical system using dangerous plug-ins. What would be the best approach for the initial scan?

a)
  1. Run the scan against production systems to achieve the most realistic results possible.

b)
  1. Run the scan during business hours.

c)
  1. Run the scan in a test environment.

d)
  1. Do not run the scan to avoid disrupting the business.

16.

Which one of the following activities is not part of the vulnerability management life cycle?

a)
  1. Detection

b)
  1. Remediation

c)
  1. Reporting

d)
  1. Testing

17.

What approach to vulnerability scanning incorporates information from agents running on the target servers?

a)
  1. Continuous monitoring

b)
  1. Ongoing scanning

c)
  1. On-demand scanning

d)
  1. Alerting

18.

Kolin would like to use an automated web application vulnerability scanner to identify any potential security issues in an application that is about to be deployed in his environment. Which one of the following tools is least likely to meet his needs?

a)
  1. ZAP

b)
  1. Nikto

c)
  1. Arachni

d)
  1. Burp Suite

19.

Jessica is reading reports from vulnerability scans run by different part of her organization using different products. She is responsible for assigning remediation resources and is having difficulty prioritizing issues from different sources. What SCAP component can help Jessica with this task?

a)
  1. CVSS

b)
  1. CVE

c)
  1. CPE

d)
  1. XCCDF

20.

Sarah would like to run an external vulnerability scan on a system for PCI DSS compliance purposes. Who is authorized to complete one of these scans?

a)
  1. Any employee of the organization

b)
  1. An approved scanning vendor

c)
  1. A PCI DSS service provider

d)
  1. Any qualified individual