CompTIA Security+ SY0-701 Vulnerability Management Practice Test 2

 

Topic 16 Practice Test 2 covers Vulnerability Management for CompTIA Security+ SY0-701 and maps to objective 4.3: Explain various activities associated with vulnerability management. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Two requirements remain open in a vulnerability-management program review: tracking libraries and dependencies for known vulnerabilities and risky versions; performing another assessment after remediation. In practical terms, it is used to verify that a vulnerability was actually removed and did not remain exposed. Which TWO options close those specific gaps? Choose TWO.

  1. Proprietary threat feed
  2. Dynamic application analysis
  3. CVE
  4. Rescanning
  5. Package monitoring

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Rescanning means performing another assessment after remediation. One required function is exactly what this option provides. Proprietary threat feed may be useful elsewhere, but it is used for commercial or private threat intelligence supplied by a vendor or specialized provider.

Answer E is correct because Package monitoring means tracking libraries and dependencies for known vulnerabilities and risky versions. One required function is exactly what this option provides. CVE may be useful elsewhere, but it is used for a standardized identifier assigned to a publicly disclosed vulnerability.

Incorrect Answers

 

Answer A is incorrect because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider. The scenario calls for Package monitoring, Rescanning. Selecting this option would leave one of those required functions uncovered.

Answer B is incorrect because Dynamic application analysis means testing an application while it is running to observe behavior and identify exploitable conditions. The fixed-count answer set is Package monitoring, Rescanning; this option does not fill one of those named functions.

Answer C is incorrect because CVE means a standardized identifier assigned to a publicly disclosed vulnerability. The scenario calls for Package monitoring, Rescanning. Selecting this option would leave one of those required functions uncovered. For example, Rescanning is required for performing another assessment after remediation.

 

Question 2

Which term describes testing an application while it is running to observe behavior and identify exploitable conditions?

  1. Exception or exemption
  2. False negative
  3. Rescanning
  4. Dynamic application analysis

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Dynamic application analysis means testing an application while it is running to observe behavior and identify exploitable conditions. This is the precise fit for the scenario. Exception or exemption serves the different purpose of formally approved deviation from a security requirement under defined conditions and ownership.

Incorrect Answers

 

Answer A is incorrect because Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership. The key mismatch is functional: Dynamic application analysis addresses testing an application while it is running to observe behavior and identify exploitable conditions, the need stated by the question.

Answer B is incorrect because False negative refers to a real vulnerability that an assessment fails to detect. The concept is valid, but it does not match this stem. The required function is testing an application while it is running to observe behavior and identify exploitable conditions, which maps to Dynamic application analysis.

Answer C is incorrect because Rescanning refers to performing another assessment after remediation. The key mismatch is functional: Dynamic application analysis addresses testing an application while it is running to observe behavior and identify exploitable conditions, the need stated by the question.

 

Question 3

Which term describes ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context?

  1. Package monitoring
  2. Exposure factor
  3. Risk-based prioritization
  4. Dynamic application analysis

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Risk-based prioritization means ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. That is the function the question is testing. Dynamic application analysis would instead be used for testing an application while it is running to observe behavior and identify exploitable conditions.

Incorrect Answers

 

Answer A is incorrect because Package monitoring refers to tracking libraries and dependencies for known vulnerabilities and risky versions. The question is not asking for this function. It is testing ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context, so Risk-based prioritization is the stronger fit.

Answer B is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. The question is not asking for this function. It is testing ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context, so Risk-based prioritization is the stronger fit.

Answer D is incorrect because Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions. This could be appropriate elsewhere, but the required function is ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context; that makes Risk-based prioritization the precise choice.

 

Question 4

To verify that a vulnerability was actually removed and did not remain exposed, which security approach should be selected?

  1. Information-sharing organization
  2. Package monitoring
  3. Rescanning
  4. Open-source intelligence (OSINT)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Rescanning means performing another assessment after remediation. The deciding point is functional fit: this option covers the stated need, while Package monitoring addresses tracking libraries and dependencies for known vulnerabilities and risky versions.

Incorrect Answers

 

Answer A is incorrect because Information-sharing organization refers to an industry or community group that shares security intelligence among members. This could be appropriate elsewhere, but the required function is performing another assessment after remediation; that makes Rescanning the precise choice.

Answer B is incorrect because Package monitoring refers to tracking libraries and dependencies for known vulnerabilities and risky versions. The concept is valid, but it does not match this stem. The required function is performing another assessment after remediation, which maps to Rescanning.

Answer D is incorrect because Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity. The concept is valid, but it does not match this stem. The required function is performing another assessment after remediation, which maps to Rescanning.

 

Question 5

To identify supply-chain exposure in third-party software components, which security approach should be selected?

  1. Static application analysis
  2. Package monitoring
  3. Bug bounty program
  4. Dark-web monitoring

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Package monitoring means tracking libraries and dependencies for known vulnerabilities and risky versions. That is the function the question is testing. Static application analysis would instead be used for inspection of application code or binaries without executing them.

Incorrect Answers

 

Answer A is incorrect because Static application analysis refers to inspection of application code or binaries without executing them. The key mismatch is functional: Package monitoring addresses tracking libraries and dependencies for known vulnerabilities and risky versions, the need stated by the question.

Answer C is incorrect because Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports. The concept is valid, but it does not match this stem. The required function is tracking libraries and dependencies for known vulnerabilities and risky versions, which maps to Package monitoring.

Answer D is incorrect because Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity. The key mismatch is functional: Package monitoring addresses tracking libraries and dependencies for known vulnerabilities and risky versions, the need stated by the question.

 

Question 6

To augment vulnerability and threat analysis with external public sources, which security approach should be selected?

  1. Proprietary threat feed
  2. Bug bounty program
  3. Responsible disclosure program
  4. Open-source intelligence (OSINT)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Open-source intelligence (OSINT) means publicly available information used to identify threats, exposures, or attacker activity. That is the function the question is testing. Bug bounty program would instead be used for a responsible disclosure program that offers rewards for qualifying vulnerability reports.

Incorrect Answers

 

Answer A is incorrect because Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider. The key mismatch is functional: Open-source intelligence (OSINT) addresses publicly available information used to identify threats, exposures, or attacker activity, the need stated by the question.

Answer B is incorrect because Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports. That concept can be valid in another scenario, but this question is testing publicly available information used to identify threats, exposures, or attacker activity; Open-source intelligence (OSINT) therefore fits the requirement more directly.

Answer C is incorrect because Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely. The concept is valid, but it does not match this stem. The required function is publicly available information used to identify threats, exposures, or attacker activity, which maps to Open-source intelligence (OSINT).

 

Question 7

A review during a vulnerability-management program review identifies two gaps. One requires authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused. The other requires formally approved deviation from a security requirement under defined conditions and ownership. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Dynamic application analysis
  2. Responsible disclosure program
  3. Risk-based prioritization
  4. Penetration testing
  5. Exception or exemption

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Penetration testing means authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused. This option satisfies a specific requirement in the stem; Dynamic application analysis serves testing an application while it is running to observe behavior and identify exploitable conditions and therefore is not interchangeable with it.

Answer E is correct because Exception or exemption means formally approved deviation from a security requirement under defined conditions and ownership. This selection maps directly to one of the named needs. Responsible disclosure program addresses a defined process for external researchers to report security vulnerabilities safely, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Dynamic application analysis means testing an application while it is running to observe behavior and identify exploitable conditions. The fixed-count answer set is Penetration testing, Exception or exemption; this option does not fill one of those named functions.

Answer B is incorrect because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely. Every answer slot must map to a stated requirement. The correct set is Penetration testing, Exception or exemption, so this option cannot replace one of those selections.

Answer C is incorrect because Risk-based prioritization means ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. The question requires exactly 2 selections: Penetration testing, Exception or exemption. This option falls outside that required set. For example, Penetration testing is required for authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused.

 

Question 8

Which responsible disclosure program offers rewards for qualifying vulnerability reports?

  1. Bug bounty program
  2. Exception or exemption
  3. CVE
  4. Responsible disclosure program

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports. That makes it the best answer here; Responsible disclosure program addresses a defined process for external researchers to report security vulnerabilities safely, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership. The question is not asking for this function. It is testing a responsible disclosure program that offers rewards for qualifying vulnerability reports, so Bug bounty program is the stronger fit.

Answer C is incorrect because CVE refers to a standardized identifier assigned to a publicly disclosed vulnerability. That concept can be valid in another scenario, but this question is testing a responsible disclosure program that offers rewards for qualifying vulnerability reports; Bug bounty program therefore fits the requirement more directly.

Answer D is incorrect because Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely. The key mismatch is functional: Bug bounty program addresses a responsible disclosure program that offers rewards for qualifying vulnerability reports, the need stated by the question.

 

Question 9

A security plan created during a vulnerability-management program review must provide publicly available information used to identify threats, exposures, or attacker activity, commercial or private threat intelligence supplied by a vendor or specialized provider, and estimated percentage of asset value lost if a specific risk event occurs. Which THREE options should be selected? Choose THREE.

  1. CVSS
  2. Exposure factor
  3. CVE
  4. Proprietary threat feed
  5. Dark-web monitoring
  6. Open-source intelligence (OSINT)

Correct Answers: B, D, F

Correct Answers

 

 

Answer B is correct because Exposure factor means the estimated percentage of asset value lost if a specific risk event occurs. The fixed-count item needs this function in the answer set. Dark-web monitoring covers observation of hidden or criminal online sources for leaked credentials, data, or threat activity, a different requirement.

Answer D is correct because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider. It belongs in the fixed-count answer set because it covers one of the stated requirements. Dark-web monitoring instead serves observation of hidden or criminal online sources for leaked credentials, data, or threat activity and cannot replace this function.

Answer F is correct because Open-source intelligence (OSINT) means publicly available information used to identify threats, exposures, or attacker activity. One required function is exactly what this option provides. CVE may be useful elsewhere, but it is used for a standardized identifier assigned to a publicly disclosed vulnerability.

Incorrect Answers

 

Answer A is incorrect because CVSS means a standardized scoring framework for describing vulnerability severity characteristics. Every answer slot must map to a stated requirement. The correct set is Open-source intelligence (OSINT), Exposure factor, Proprietary threat feed, so this option cannot replace one of those selections.

Answer C is incorrect because CVE means a standardized identifier assigned to a publicly disclosed vulnerability. The required choices are Open-source intelligence (OSINT), Exposure factor, Proprietary threat feed. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Dark-web monitoring means observation of hidden or criminal online sources for leaked credentials, data, or threat activity. The question requires exactly 3 selections: Open-source intelligence (OSINT), Exposure factor, Proprietary threat feed. This option falls outside that required set.

 

Question 10

A review during a vulnerability-management program review identifies two gaps. One requires responsible disclosure program that offers rewards for qualifying vulnerability reports. The other requires alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Bug bounty program
  2. Compensating control
  3. Open-source intelligence (OSINT)
  4. Exception or exemption
  5. CVE

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports. The fixed-count item needs this function in the answer set. Exception or exemption covers formally approved deviation from a security requirement under defined conditions and ownership, a different requirement.

Answer B is correct because Compensating control means an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. One required function is exactly what this option provides. Open-source intelligence (OSINT) may be useful elsewhere, but it is used for publicly available information used to identify threats, exposures, or attacker activity.

Incorrect Answers

 

Answer C is incorrect because Open-source intelligence (OSINT) means publicly available information used to identify threats, exposures, or attacker activity. The fixed-count answer set is Bug bounty program, Compensating control; this option does not fill one of those named functions.

Answer D is incorrect because Exception or exemption means formally approved deviation from a security requirement under defined conditions and ownership. Every answer slot must map to a stated requirement. The correct set is Bug bounty program, Compensating control, so this option cannot replace one of those selections.

Answer E is incorrect because CVE means a standardized identifier assigned to a publicly disclosed vulnerability. The question requires exactly 2 selections: Bug bounty program, Compensating control. This option falls outside that required set. For example, Bug bounty program is required for a responsible disclosure program that offers rewards for qualifying vulnerability reports.

 

Question 11

What is a standardized scoring framework for describing vulnerability severity characteristics?

  1. Exposure factor
  2. Proprietary threat feed
  3. CVSS
  4. Dynamic application analysis

Correct Answer: C

Correct Answer

 

 

Answer C is correct because CVSS means a standardized scoring framework for describing vulnerability severity characteristics. That makes it the best answer here; Exposure factor addresses the estimated percentage of asset value lost if a specific risk event occurs, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. This could be appropriate elsewhere, but the required function is a standardized scoring framework for describing vulnerability severity characteristics; that makes CVSS the precise choice.

Answer B is incorrect because Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider. The question is not asking for this function. It is testing a standardized scoring framework for describing vulnerability severity characteristics, so CVSS is the stronger fit.

Answer D is incorrect because Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions. The scenario instead requires a standardized scoring framework for describing vulnerability severity characteristics, which is why CVSS is the better answer; this option serves the different function defined above.

 

Question 12

To receive and remediate legitimate findings without encouraging uncontrolled disclosure, which security approach should be selected?

  1. CVE
  2. Compensating control
  3. Static application analysis
  4. Responsible disclosure program

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely. That makes it the best answer here; Static application analysis addresses inspection of application code or binaries without executing them, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because CVE refers to a standardized identifier assigned to a publicly disclosed vulnerability. The key mismatch is functional: Responsible disclosure program addresses a defined process for external researchers to report security vulnerabilities safely, the need stated by the question.

Answer B is incorrect because Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. That concept can be valid in another scenario, but this question is testing a defined process for external researchers to report security vulnerabilities safely; Responsible disclosure program therefore fits the requirement more directly.

Answer C is incorrect because Static application analysis refers to inspection of application code or binaries without executing them. That concept can be valid in another scenario, but this question is testing a defined process for external researchers to report security vulnerabilities safely; Responsible disclosure program therefore fits the requirement more directly.

 

Question 13

A review during a vulnerability-management program review identifies two gaps. One requires inspection of application code or binaries without executing them. The other requires standardized scoring framework for describing vulnerability severity characteristics. Which TWO options should be included in the remediation plan? Choose TWO.

  1. CVSS
  2. Responsible disclosure program
  3. Static application analysis
  4. Open-source intelligence (OSINT)
  5. CVE

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because CVSS means a standardized scoring framework for describing vulnerability severity characteristics. It belongs in the fixed-count answer set because it covers one of the stated requirements. CVE instead serves a standardized identifier assigned to a publicly disclosed vulnerability and cannot replace this function.

Answer C is correct because Static application analysis means inspection of application code or binaries without executing them. This selection maps directly to one of the named needs. Responsible disclosure program addresses a defined process for external researchers to report security vulnerabilities safely, so it does not satisfy the same slot.

Incorrect Answers

 

Answer B is incorrect because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely. The scenario calls for Static application analysis, CVSS. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Open-source intelligence (OSINT) means publicly available information used to identify threats, exposures, or attacker activity. The question requires exactly 2 selections: Static application analysis, CVSS. This option falls outside that required set. For example, CVSS is required for a standardized scoring framework for describing vulnerability severity characteristics.

Answer E is incorrect because CVE means a standardized identifier assigned to a publicly disclosed vulnerability. The question requires exactly 2 selections: Static application analysis, CVSS. This option falls outside that required set. For example, CVSS is required for a standardized scoring framework for describing vulnerability severity characteristics.

 

Question 14

To avoid wasting remediation effort by confirming findings before action, which security approach should be selected?

  1. Compensating control
  2. Package monitoring
  3. Dark-web monitoring
  4. False positive

Correct Answer: D

Correct Answer

 

 

Answer D is correct because False positive means a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. This matches the requirement as written. Compensating control can be valid in another context, but it is used for an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately.

Incorrect Answers

 

Answer A is incorrect because Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. The concept is valid, but it does not match this stem. The required function is a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context, which maps to False positive.

Answer B is incorrect because Package monitoring refers to tracking libraries and dependencies for known vulnerabilities and risky versions. The question is not asking for this function. It is testing a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context, so False positive is the stronger fit.

Answer C is incorrect because Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity. The question is not asking for this function. It is testing a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context, so False positive is the stronger fit.

 

Question 15

To find runtime vulnerabilities from an external or black-box perspective, which security approach should be selected?

  1. Compensating control
  2. Exception or exemption
  3. Dynamic application analysis
  4. False negative

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Dynamic application analysis means testing an application while it is running to observe behavior and identify exploitable conditions. This matches the requirement as written. False negative can be valid in another context, but it is used for a real vulnerability that an assessment fails to detect.

Incorrect Answers

 

Answer A is incorrect because Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. This could be appropriate elsewhere, but the required function is testing an application while it is running to observe behavior and identify exploitable conditions; that makes Dynamic application analysis the precise choice.

Answer B is incorrect because Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership. The question is not asking for this function. It is testing testing an application while it is running to observe behavior and identify exploitable conditions, so Dynamic application analysis is the stronger fit.

Answer D is incorrect because False negative refers to a real vulnerability that an assessment fails to detect. This could be appropriate elsewhere, but the required function is testing an application while it is running to observe behavior and identify exploitable conditions; that makes Dynamic application analysis the precise choice.

 

Question 16

Which term describes commercial or private threat intelligence supplied by a vendor or specialized provider?

  1. Proprietary threat feed
  2. Dynamic application analysis
  3. Bug bounty program
  4. False negative

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider. That is the function the question is testing. False negative would instead be used for a real vulnerability that an assessment fails to detect.

Incorrect Answers

 

Answer B is incorrect because Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions. This could be appropriate elsewhere, but the required function is commercial or private threat intelligence supplied by a vendor or specialized provider; that makes Proprietary threat feed the precise choice.

Answer C is incorrect because Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports. That concept can be valid in another scenario, but this question is testing commercial or private threat intelligence supplied by a vendor or specialized provider; Proprietary threat feed therefore fits the requirement more directly.

Answer D is incorrect because False negative refers to a real vulnerability that an assessment fails to detect. The concept is valid, but it does not match this stem. The required function is commercial or private threat intelligence supplied by a vendor or specialized provider, which maps to Proprietary threat feed.

 

Question 17

To recognize that absence of a scanner finding does not prove absence of risk, which security approach should be selected?

  1. Open-source intelligence (OSINT)
  2. False negative
  3. Information-sharing organization
  4. False positive

Correct Answer: B

Correct Answer

 

 

Answer B is correct because False negative means a real vulnerability that an assessment fails to detect. That makes it the best answer here; False positive addresses a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity. The scenario instead requires a real vulnerability that an assessment fails to detect, which is why False negative is the better answer; this option serves the different function defined above.

Answer C is incorrect because Information-sharing organization refers to an industry or community group that shares security intelligence among members. The question is not asking for this function. It is testing a real vulnerability that an assessment fails to detect, so False negative is the stronger fit.

Answer D is incorrect because False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. That concept can be valid in another scenario, but this question is testing a real vulnerability that an assessment fails to detect; False negative therefore fits the requirement more directly.

 

Question 18

During a vulnerability-management program review, the team has two independent requirements: (1) formally approved deviation from a security requirement under defined conditions and ownership; and (2) performing another assessment after remediation. In practical terms, it is used to verify that a vulnerability was actually removed and did not remain exposed. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Rescanning
  2. Information-sharing organization
  3. Exposure factor
  4. CVSS
  5. Exception or exemption

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Rescanning means performing another assessment after remediation. It belongs in the fixed-count answer set because it covers one of the stated requirements. CVSS instead serves a standardized scoring framework for describing vulnerability severity characteristics and cannot replace this function.

Answer E is correct because Exception or exemption means formally approved deviation from a security requirement under defined conditions and ownership. This option satisfies a specific requirement in the stem; Exposure factor serves the estimated percentage of asset value lost if a specific risk event occurs and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Information-sharing organization means an industry or community group that shares security intelligence among members. The scenario calls for Exception or exemption, Rescanning. Selecting this option would leave one of those required functions uncovered. For example, Exception or exemption is required for formally approved deviation from a security requirement under defined conditions and ownership.

Answer C is incorrect because Exposure factor means the estimated percentage of asset value lost if a specific risk event occurs. The scenario calls for Exception or exemption, Rescanning. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because CVSS means a standardized scoring framework for describing vulnerability severity characteristics. The required choices are Exception or exemption, Rescanning. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 19

To lower exposure until a permanent fix is available, which security approach should be selected?

  1. Exposure factor
  2. Compensating control
  3. False negative
  4. Exception or exemption

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Compensating control means an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. The requirement maps directly to this function, whereas Exposure factor is aimed at the estimated percentage of asset value lost if a specific risk event occurs.

Incorrect Answers

 

Answer A is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. The key mismatch is functional: Compensating control addresses an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately, the need stated by the question.

Answer C is incorrect because False negative refers to a real vulnerability that an assessment fails to detect. The key mismatch is functional: Compensating control addresses an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately, the need stated by the question.

Answer D is incorrect because Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership. The question is not asking for this function. It is testing an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately, so Compensating control is the stronger fit.

 

Question 20

To discover candidate vulnerabilities across systems and applications, which security approach should be selected?

  1. Vulnerability scanning
  2. Exposure factor
  3. Dynamic application analysis
  4. Proprietary threat feed

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Vulnerability scanning means automated probing and assessment used to identify known weaknesses and configuration problems. The deciding point is functional fit: this option covers the stated need, while Proprietary threat feed addresses commercial or private threat intelligence supplied by a vendor or specialized provider.

Incorrect Answers

 

Answer B is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. This could be appropriate elsewhere, but the required function is automated probing and assessment used to identify known weaknesses and configuration problems; that makes Vulnerability scanning the precise choice.

Answer C is incorrect because Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions. This could be appropriate elsewhere, but the required function is automated probing and assessment used to identify known weaknesses and configuration problems; that makes Vulnerability scanning the precise choice.

Answer D is incorrect because Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider. This could be appropriate elsewhere, but the required function is automated probing and assessment used to identify known weaknesses and configuration problems; that makes Vulnerability scanning the precise choice.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!