NEW
Font size
WorksheetsChapter 6: Designing a Vulnerability Management Program
Total questions: 20
Worksheet time: 20mins
What federal law requires the use of vulnerability scanning on information systems operated by federal government agencies?
HIPAA
GLBA
FISMA
FERPA
Which one of the following industry standards describes a standard approach for setting up an information security management system?
OWASP
CIS
ISO 27002
ISO 27001
What tool can administrators use to help identify the systems present on a network prior to conducting vulnerability scans?
Asset inventory
Web application assessment
Router
DLP
Tonya is configuring vulnerability scans for a system that is subject to the PCI DSS compliance standard. What is the minimum frequency with which she must conduct scans?
Daily
Weekly
Monthly
Quarterly
Which one of the following is not an example of a vulnerability scanning tool?
Nikto
Snort
Nessus
OpenVAS
Bethany is the vulnerability management specialist for a large retail organization. She completed her last PCI DSS compliance scan in March. In April, the organization upgraded their point-of-sale system, and Bethany is preparing to conduct new scans. When must she complete the new scan?
Immediately.
June.
December.
No scans are required.
Renee is configuring her vulnerability management solution to perform credentialed scans of servers on her network. What type of account should she provide to the scanner?
Domain administrator
Local administrator
Root
Read-only
Jason is writing a report about a potential security vulnerability in a software product and wishes to use standardized product names to ensure that other security analysts understand the report. Which SCAP component can Jason turn to for assistance?
CVSS
CVE
CPE
OVAL
Bill would like to run an internal vulnerability scan on a system for PCI DSS compliance purposes. Who is authorized to complete one of these scans?
Any employee of the organization
An approved scanning vendor
A PCI DSS service provider
Any qualified individual
Which type of organization is the most likely to face a regulatory requirement to conduct vulnerability scans?
Bank
Hospital
Government agency
Doctor's office
Which one of the following organizations focuses on providing tools and advice for secure web application development?
OWASP
CIS
NIST
Microsoft
What term describes an organization's willingness to tolerate risk in their computing environment?
Risk landscape
Risk appetite
Risk level
Risk adaptation
Which one of the following factors is least likely to impact vulnerability scanning schedules?
Regulatory requirements
Technical constraints
Business constraints
Staff availability
Barry placed all of his organization's credit card processing systems on an isolated network dedicated to card processing. He has implemented appropriate segmentation controls to limit the scope of PCI DSS to those systems through the use of VLANs and firewalls. When Barry goes to conduct vulnerability scans for PCI DSS compliance purposes, what systems must he scan?
Customer systems
Systems on the isolated network
Systems on the general enterprise network
Ryan is planning to conduct a vulnerability scan of a business-critical system using dangerous plug-ins. What would be the best approach for the initial scan?
Run the scan against production systems to achieve the most realistic results possible.
Run the scan during business hours.
Run the scan in a test environment.
Do not run the scan to avoid disrupting the business.
Which one of the following activities is not part of the vulnerability management life cycle?
Detection
Remediation
Reporting
Testing
What approach to vulnerability scanning incorporates information from agents running on the target servers?
Continuous monitoring
Ongoing scanning
On-demand scanning
Alerting
Kolin would like to use an automated web application vulnerability scanner to identify any potential security issues in an application that is about to be deployed in his environment. Which one of the following tools is least likely to meet his needs?
ZAP
Nikto
Arachni
Burp Suite
Jessica is reading reports from vulnerability scans run by different part of her organization using different products. She is responsible for assigning remediation resources and is having difficulty prioritizing issues from different sources. What SCAP component can help Jessica with this task?
CVSS
CVE
CPE
XCCDF
Sarah would like to run an external vulnerability scan on a system for PCI DSS compliance purposes. Who is authorized to complete one of these scans?
Any employee of the organization
An approved scanning vendor
A PCI DSS service provider
Any qualified individual
