Courseiva

CCNA Cysa Vulnerability Management Questions

75 of 124 questions · Page 1/2 · Cysa Vulnerability Management topic · Answers revealed

1
MCQeasy

A security analyst is reviewing a vulnerability scan report and notices a plugin that identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The CVSS vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which attack vector is indicated?

A.Network
B.Adjacent network
C.Local
D.Physical
AnswerA

AV:N (Attack Vector: Network) means the vulnerable component is bound to the network stack and the attacker's path to exploit lies through a routable network connection, potentially even across the internet, rather than requiring physical or local access. This is the highest-severity attack vector value because it maximizes the pool of potential attackers, contributing to this vulnerability's near-maximum CVSS base score of 9.8 alongside low complexity and no required privileges or user interaction.

Why this answer

AV:N indicates network attack vector, meaning the vulnerability can be exploited remotely over the network without any physical or local access.

2
MCQhard

A vulnerability management team is evaluating a critical vulnerability in a legacy application that cannot be patched. The application is used by a small number of users internally. Which of the following is the best compensating control to reduce risk?

A.Implement network segmentation to restrict access to the application
B.Enable application whitelisting on all endpoints
C.Encrypt all data in transit
D.Disable the application until a patch is available
AnswerA

Implementing network segmentation isolates the vulnerable legacy application within a restricted network zone, such as a dedicated VLAN or DMZ. This control significantly reduces the attack surface by ensuring only authorized users and systems can communicate with the application, effectively mitigating the risk of lateral movement and unauthorized exploitation when no patch is available.

Why this answer

When patching is not possible, compensating controls like network segmentation can limit exposure. Disabling the application would impact business. Application whitelisting might be too broad.

Encryption doesn't prevent exploitation of the vulnerability.

3
MCQeasy

An organization is implementing a patch management process. Which of the following is the BEST practice before deploying patches to production systems?

A.Disable automatic updates and deploy patches manually without testing
B.Immediately apply all patches to production to minimize exposure time
C.Test patches in a staging environment that mirrors production
D.Only apply patches that have a CVSS score of 9.0 or higher
AnswerC

Validating patches within a dedicated staging environment that closely replicates the production architecture is a fundamental security best practice. This process allows administrators to identify compatibility issues, assess performance impacts, and ensure system stability before deploying the updates to live, mission-critical systems.

Why this answer

Best practice for patch management includes testing patches in a staging environment that closely mirrors production before deploying to production. This allows identification of compatibility issues, performance impacts, or conflicts without disrupting critical systems. It balances security with operational stability.

Exam trap

CS0-004 often tests the balance between security and availability, where candidates might choose immediate patching to minimize exposure, but best practice emphasizes testing first to avoid disruption.

How to eliminate wrong answers

Option A is wrong because disabling automatic updates and deploying manually without testing increases risk of unpatched vulnerabilities and human error; testing is essential. Option B is wrong because immediately applying all patches to production without testing can cause outages due to unforeseen issues, violating change management best practices. Option D is wrong because only applying patches with CVSS 9.0 or higher ignores other vulnerabilities that may be exploitable in the organization's context; a risk-based approach is better.

4
Multi-Selectmedium

A security analyst is conducting a vulnerability assessment of a Kubernetes cluster. Which TWO of the following are common misconfigurations that could lead to security risks? (Select TWO.)

Select 2 answers
A.Setting resource limits on containers
B.Configuring network policies to restrict traffic
C.Running containers in privileged mode
D.Using read-only root filesystems
E.Using hostPath mounts
AnswersC, E

Running containers in privileged mode grants them every Linux capability, disables seccomp and AppArmor/SELinux confinement, and exposes all host devices, effectively removing isolation between the container and the host kernel. An attacker who exploits a vulnerability in a privileged container can trivially escalate to full host control, making it one of the most dangerous container misconfigurations. During a vulnerability assessment, this should immediately be flagged as a critical finding.

Why this answer

Option C is correct because running containers in privileged mode disables the container's isolation from the host, granting access to all Linux capabilities and devices (equivalent to --privileged), which allows a compromised container to escape and control the node. Option E is correct because hostPath mounts expose a file or directory from the node's filesystem directly into the pod, so a container can read or modify sensitive host paths such as /etc, /var/run/docker.sock, or /proc, enabling privilege escalation and node compromise. Options A and D are not misconfigurations but hardening measures: resource limits mitigate denial-of-service and noisy-neighbor risks, and read-only root filesystems prevent runtime tampering with container binaries.

Option B is also a security control, not a risk, since Kubernetes NetworkPolicies restrict pod-to-pod traffic and enforce segmentation.

Exam trap

CS0-004 often tests the inversion of security best practices, so candidates must recognize that resource limits, network policies, and read-only filesystems are protections, while privileged mode and hostPath mounts are risks.

5
MCQmedium

During a vulnerability scan, an analyst identifies a plugin that reports a vulnerability with a CVSS v3.1 base score of 7.5. The vector string includes AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Which of the following is the primary impact of this vulnerability?

A.Integrity
B.Scope change
C.Availability
D.Confidentiality
AnswerC

The vector's Availability metric is A:H, meaning High, the only impact metric set above None in this string, indicating the vulnerability can fully deny access to the affected resource, for example through a crash or resource exhaustion condition, making Availability the clear primary impact and consistent with a 7.5 base score driven almost entirely by this single high-impact metric.

Why this answer

The CIA impact ratings show A:H (Availability High), meaning the vulnerability primarily impacts availability. C:N and I:N indicate no impact on confidentiality or integrity.

6
MCQmedium

A vulnerability scanner reports a plugin that identifies a web application vulnerability related to the failure to validate user input, allowing an attacker to inject malicious scripts that execute in other users' browsers. Which OWASP Top 10 category does this vulnerability fall under?

A.Injection
B.Security Misconfiguration
C.Cryptographic Failures
D.Broken Access Control
AnswerA

Injection vulnerabilities occur when untrusted user input is interpreted as part of a command or query, leading to unauthorized execution. In OWASP frameworks, Cross-Site Scripting (XSS) is classified as a form of injection because malicious scripts are injected into trusted web applications to execute in the victim's browser.

Why this answer

The description matches cross-site scripting (XSS), which is part of the OWASP Top 10 category 'Injection' (formerly separate, but in 2021 XSS is included in Injection).

7
Multi-Selecteasy

A security analyst is selecting tools for vulnerability management. Which THREE of the following are vulnerability scanning tools?

Select 3 answers
A.Lynis
B.Nessus
C.Wireshark
D.Qualys
E.OpenVAS
AnswersB, D, E

Nessus is a commercial vulnerability scanner developed by Tenable that actively scans hosts and network services, comparing software versions and configurations against a comprehensive plugin database of known Common Vulnerabilities and Exposures (CVEs). It supports credentialed scans, agent-based scanning, and integration with patch management and SIEM platforms, making it a primary tool for continuous vulnerability management. This directly matches the goal of identifying exploitable weaknesses across an enterprise.

Why this answer

Nessus (B) is a commercial vulnerability scanner from Tenable that performs credentialed and uncredentialed scans to detect missing patches, misconfigurations, and CVEs, making it a core vulnerability management tool. Qualys (D) is a cloud-based vulnerability management platform whose QualysGuard/VMDR scanners continuously assess hosts and web applications for vulnerabilities, so it clearly belongs in this category. OpenVAS (E), maintained as the Greenbone Vulnerability Management (GVM) scanner, is an open-source vulnerability scanner that uses network vulnerability tests (NVTs) to identify known flaws, qualifying it as a scanning tool.

Lynis (A) is a host-based security auditing tool that checks system hardening and compliance rather than scanning for vulnerabilities across assets, and Wireshark (C) is a packet capture and protocol analysis tool used for traffic inspection, not vulnerability scanning.

Exam trap

CS0-004 often tests tool categorization, so candidates confuse host auditing tools like Lynis or protocol analyzers like Wireshark with true vulnerability scanners, which enumerate CVEs against targets.

8
MCQhard

A security analyst is evaluating a vulnerability with CVSS v3.1 base score: AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N. Which of the following best describes the scope and impact of this vulnerability?

A.Scope is unchanged, high impact on confidentiality only
B.Scope is changed, high impact on integrity only
C.Scope is unchanged, high impact on confidentiality and integrity
D.Scope is changed, high impact on confidentiality only
AnswerD

This is correct: the vector specifies S:C (Scope Changed) and C:H (high confidentiality impact), while integrity and availability are None (I:N/A:N). A Changed scope means the vulnerability affects resources outside the vulnerable component's security authority, and the only rated impact is disclosure of sensitive information. These values exactly match the analyst's finding.

Why this answer

The CVSS v3.1 vector AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N indicates Scope is Changed (S:C) and Confidentiality impact is High (C:H), while Integrity (I:N) and Availability (A:N) impacts are None. Therefore, the correct description is scope changed with high impact on confidentiality only. The other options misstate either the scope or the impacted security property.

Exam trap

CS0-004 often tests precise CVSS vector parsing, so candidates who skim the string and assume multiple impacts or unchanged scope (because only one impact is High) select the wrong description.

How to eliminate wrong answers

Option A is wrong because it claims scope is unchanged, but the vector specifies S:C (Scope Changed). Option B is wrong because it claims high impact on integrity, but the vector shows I:N (Integrity None). Option C is wrong because it claims scope unchanged and high impact on both confidentiality and integrity, but the vector shows S:C and I:N.

9
Multi-Selecthard

A security analyst is reviewing a containerized application for vulnerabilities. The analyst uses a container image scanner and identifies several issues. Which THREE of the following are common container and Kubernetes misconfigurations that the analyst should prioritize? (Choose three.)

Select 3 answers
A.Overly permissive RBAC configurations
B.Keeping container images up to date
C.Running containers with the 'privileged' flag
D.Implementing network policies to restrict pod communication
E.Using hostPath mounts
AnswersA, C, E

Overly permissive RBAC bindings grant cluster-wide or wildcard permissions, letting a compromised workload escalate privileges or reach other namespaces. Auditing roles, ClusterRoleBindings and service accounts for excessive verbs and resources is a priority Kubernetes hardening check.

Why this answer

Option A (Overly permissive RBAC configurations) is correct because Kubernetes RBAC roles bound with wildcards or cluster-admin privileges grant excessive permissions, enabling privilege escalation and lateral movement across the cluster. Option C (Running containers with the 'privileged' flag) is correct because a privileged container disables most namespace isolation and gains near-full access to host devices and kernel capabilities, effectively breaking container boundaries. Option E (Using hostPath mounts) is correct because hostPath volumes expose node filesystem paths to pods, allowing access to sensitive host files such as /var/run/docker.sock or /etc, which can lead to node compromise.

Option B is not a misconfiguration but a security best practice, since updating images remediates known CVEs rather than introducing risk. Option D is also a recommended hardening control, as network policies restrict pod-to-pod traffic and reduce lateral movement, so it is not a misconfiguration to prioritize.

10
Multi-Selectmedium

A vulnerability management team is prioritizing vulnerabilities for remediation. They have a list of vulnerabilities with different characteristics. According to best practices, which TWO factors should be considered when prioritizing vulnerabilities? (Select TWO.)

Select 2 answers
A.The CVSS base score
B.The asset's criticality to the business
C.The availability of a patch
D.Whether the vulnerability is listed in the CISA KEV catalog
E.The number of open ports on the asset
AnswersB, D

Asset criticality is the correct primary driver for prioritization because it directly captures the potential business impact if confidentiality, integrity, or availability is compromised. A vulnerability on a server that processes financial transactions or contains protected health information poses far greater risk than the same CVE on an internet-facing demo server with no sensitive data. This aligns with risk-based vulnerability management, where risk equals the likelihood of exploitation multiplied by the consequence to the business.

Why this answer

Option B is correct because an asset's criticality to the business determines the real-world impact of exploitation, so a high-severity vulnerability on a mission-critical server should be remediated before the same vulnerability on a low-value test machine. Option D is correct because the CISA Known Exploited Vulnerabilities (KEV) catalog identifies vulnerabilities that are actively exploited in the wild, which is a strong signal to prioritize them regardless of other factors. The CVSS base score (A) reflects intrinsic severity but not business context or exploitation activity, so it is only one input rather than a standalone prioritization factor.

Patch availability (C) affects remediation timing but does not by itself indicate risk priority, and the number of open ports (E) is an attack-surface indicator, not a standard vulnerability prioritization criterion.

Exam trap

The trap is treating CVSS base score as the sole prioritization metric; candidates who select it ignore that business criticality and active exploitation (KEV) are what convert technical severity into actual organizational risk.

11
Multi-Selectmedium

A security analyst is performing a vulnerability assessment and needs to identify potential misconfigurations in a Kubernetes cluster. Which TWO of the following are common Kubernetes misconfigurations that should be checked? (Select TWO.)

Select 2 answers
A.Privileged containers
B.Using network policies
C.hostPath mounts
D.Running containers as non-root user
E.Using ConfigMaps for non-sensitive data
AnswersA, C

Privileged containers run with all Linux capabilities and disable isolation mechanisms such as seccomp, AppArmor, or SELinux, effectively granting the process root-equivalent access to the host kernel and devices. This means a malicious or compromised workload inside the container can directly attempt to escape the container and compromise the underlying node. Thus, enabling privileged mode is a critical misconfiguration that should be avoided in standard deployments.

Why this answer

Option A (Privileged containers) is correct because running a container with securityContext.privileged: true grants it nearly all capabilities of the host, effectively removing container isolation and allowing access to host devices and kernel features, which is a classic Kubernetes misconfiguration flagged by tools like kube-bench and CIS benchmarks. Option C (hostPath mounts) is correct because mounting a host directory or file into a pod (volumes.hostPath) exposes the node's filesystem to the container, enabling privilege escalation, persistence, or node compromise if an attacker gains code execution. Option B (Using network policies) is not a misconfiguration — network policies are a security best practice that restrict pod-to-pod traffic, and their absence would be the issue, not their use.

Option D (Running containers as non-root user) is not a misconfiguration — setting runAsNonRoot: true or a non-zero runAsUser is a hardening measure that reduces risk. Option E (Using ConfigMaps for non-sensitive data) is not a misconfiguration — ConfigMaps are the intended mechanism for non-confidential configuration data, whereas Secrets should be used for sensitive values.

Exam trap

CS0-004 often tests whether candidates can distinguish between secure configurations (network policies, non-root users, ConfigMaps for non-sensitive data) and actual misconfigurations (privileged containers, hostPath mounts), so candidates must know which options represent risks rather than best practices.

12
MCQmedium

During a vulnerability assessment, a security analyst discovers a web application that is vulnerable to SQL injection. The application is a legacy system that cannot be easily patched. The analyst recommends implementing a web application firewall (WAF) rule to block malicious SQL patterns. Which type of control does this represent?

A.Corrective control
B.Preventive control
C.Detective control
D.Compensating control
AnswerD

A compensating control is an alternative safeguard put in place to mitigate risk when a primary security control, such as applying a vendor patch, is technically or operationally unfeasible. By configuring the Web Application Firewall to block exploits targeting the specific vulnerability, the organization successfully reduces the associated risk to an acceptable level without modifying the underlying application code.

Why this answer

A compensating control is an alternative control that mitigates risk when the primary control (patch) cannot be applied.

13
MCQmedium

An organization is implementing configuration management and decides to use CIS Benchmarks to harden their servers. They choose Level 1 benchmarks for most servers but Level 2 for highly sensitive systems. What is the key difference between Level 1 and Level 2 CIS benchmarks?

A.Level 1 is more restrictive and secure than Level 2
B.Level 2 guidelines are more restrictive and may impact system functionality
C.Level 1 is for cloud systems, Level 2 for on-premises
D.Level 2 is only for DoD environments
AnswerB

Correct. Level 2 benchmarks apply defense-in-depth hardening intended for high-security environments and often disable features, ports, or services that could affect usability or compatibility, so CIS explicitly recommends testing Level 2 changes before production deployment due to potential functional impact.

Why this answer

CIS Level 1 benchmarks are basic security recommendations that can be implemented with minimal impact, while Level 2 includes more restrictive controls that may affect system functionality but provide higher security.

14
Multi-Selecteasy

A security analyst is setting up a vulnerability management program and needs to select tools for container image scanning. Which THREE of the following are commonly used container image scanning tools? (Select THREE.)

Select 3 answers
A.Snyk
B.OpenVAS
C.Burp Suite
D.Clair
E.Trivy
AnswersA, D, E

Snyk scans container images for known vulnerabilities in OS packages and application dependencies, integrating into CI pipelines and registries. It is a widely adopted container image scanning tool, satisfying the selection criterion for this programme.

Why this answer

Snyk (A) is a widely used container image scanning tool that detects known vulnerabilities in OS packages and application dependencies within images, integrating into CI/CD pipelines. Clair (D) is an open-source static analysis tool from CoreOS/Quay that scans container image layers against vulnerability databases to report known CVEs. Trivy (E) is an Aqua Security open-source scanner that detects OS package and language-specific dependency vulnerabilities, misconfigurations, and secrets in container images.

OpenVAS (B) is a network vulnerability scanner for hosts and services, not a container image scanner, and Burp Suite (C) is a web application security testing proxy, so neither is designed for scanning container images.

Exam trap

The trap is picking a well-known security tool (OpenVAS, Burp) that scans networks or web apps rather than container images — candidates who don't distinguish scanner categories will select the wrong tool.

15
MCQmedium

A company uses Qualys to scan their internal network. The scan report shows a vulnerability with plugin output indicating that the server is running a version of Apache httpd vulnerable to CVE-2023-1234. The asset is a development web server that is not exposed to the internet. The CVSS score is 7.5 (High). However, the EPSS score is 0.001 (very low). Which of the following should be the primary factor in prioritizing this vulnerability?

A.The CVSS score of 7.5 indicates high severity, so it should be remediated immediately.
B.The EPSS score of 0.001 indicates very low exploitability, so remediation can be delayed.
C.The asset is a development server not exposed to the internet, so remediation should be scheduled during normal maintenance.
D.The vulnerability is in Apache httpd, which is widely used, so it must be patched within 24 hours.
AnswerC

This option correctly synthesizes business context and risk-based vulnerability management. Because the asset is a non-production development server isolated from the internet, the actual risk of exploitation is significantly mitigated. Combining this low exposure with a low EPSS score justifies scheduling the patch during routine maintenance windows rather than disrupting operations with an emergency deployment.

Why this answer

Since the EPSS score is very low, the likelihood of exploitation in the wild is minimal. Additionally, the asset is not internet-facing, reducing exposure. The best approach is to consider the business context and asset criticality; development servers may be lower priority.

However, among the options, the EPSS score is a strong indicator of exploitability. But given the low EPSS, the vulnerability might be deprioritized. The question asks for primary factor; business context (asset criticality and exposure) is key.

But options include both EPSS and business context. The answer should be business context because the asset is internal and EPSS low, but business context might still prioritize if critical. However, in this scenario, the development server is likely not critical.

The most appropriate is to consider the business context including asset criticality and exposure.

16
MCQmedium

A web application security tester uses Burp Suite to test an API endpoint. The tester sends a request with a modified HTTP method and discovers that the API accepts DELETE requests on an endpoint that should only allow GET. This is an example of which OWASP Top 10 vulnerability?

A.Injection
B.Security Misconfiguration
C.Server-Side Request Forgery (SSRF)
D.Broken Access Control
AnswerD

Broken access control is the correct answer because it directly describes a failure to enforce restrictions on what authenticated users are allowed to do. By manipulating parameters, headers, or API endpoints in Burp Suite, testers can identify flaws like Insecure Direct Object References (IDOR) or privilege escalation, which allow unauthorized data access.

Why this answer

Improper handling of HTTP methods can lead to broken access control, allowing unauthorized actions.

17
MCQhard

An organization uses Qualys for vulnerability scanning. After a scan, the security team identifies a vulnerability with an EPSS score of 0.95 and that appears in the CISA KEV catalog. However, the affected asset is a non-critical development server with no internet access. According to the vulnerability lifecycle, what should be the analyst's NEXT action?

A.Apply a compensating control, such as a firewall rule blocking access to the server.
B.Escalate the vulnerability to management for emergency patching.
C.Document the finding and schedule remediation during the next regular maintenance window.
D.Immediately patch the server within 48 hours due to the high EPSS score.
AnswerC

Incorporating both vulnerability severity and business context is fundamental to risk-based vulnerability management. Since the asset is non-critical and isolated from the internet, the overall risk is low despite a high EPSS score, making it appropriate to document the vulnerability and remediate it during the next scheduled maintenance window without disrupting business operations.

Why this answer

Despite high EPSS and KEV listing, the asset's low business context (non-critical, no internet access) reduces risk; the analyst should prioritize based on business context, likely scheduling remediation with lower urgency.

18
MCQhard

During a web application penetration test, a security analyst uses a DAST tool and discovers that the application is vulnerable to Server-Side Request Forgery (SSRF). According to the OWASP Top 10 2021, under which category does SSRF fall?

A.A03: Injection
B.A01: Broken Access Control
C.A06: Vulnerable and Outdated Components
D.A10: Server-Side Request Forgery (SSRF)
AnswerD

Server-Side Request Forgery is explicitly categorized as A10 in the OWASP Top 10 2021. This vulnerability occurs when a web application fetches a remote resource without validating the user-supplied URL, allowing attackers to coerce the application into sending crafted requests to unexpected destinations, such as internal loopback addresses, metadata services, or private backend systems.

Why this answer

In the OWASP Top 10 2021, Server-Side Request Forgery (SSRF) was added as a new category, A10: Server-Side Request Forgery (SSRF). This category specifically addresses vulnerabilities where an attacker can induce the server to make requests to unintended locations, such as internal services or external systems.

Exam trap

CS0-004 often tests the updated OWASP Top 10 2021 categories, where candidates might incorrectly place SSRF under A03: Injection due to its historical association, but it is now a separate category A10.

How to eliminate wrong answers

Option A is wrong because A03: Injection covers injection flaws like SQL, NoSQL, and OS command injection, but SSRF is not classified as injection in the 2021 list. Option B is wrong because A01: Broken Access Control deals with access control weaknesses, not SSRF. Option C is wrong because A06: Vulnerable and Outdated Components relates to using components with known vulnerabilities, not SSRF.

19
Multi-Selecthard

An organization is implementing a patch management process. Which THREE of the following are essential steps that should be included before deploying patches to production systems? (Select the three best answers.)

Select 3 answers
A.Testing patches in a staging environment
B.Reviewing vendor security advisories for patch details
C.Performing regression testing on applications
D.Deploying patches directly to all production systems simultaneously
E.Disabling all security controls to avoid conflicts
AnswersA, B, C

Testing patches in a staging environment replicates the production configuration, including operating system versions, middleware, and sample data, to validate patch behavior and compatibility before any disruption. It allows security and IT teams to detect conflicts, broken dependencies, and performance degradations early, and to develop rollback procedures. This process is foundational to a mature patch management lifecycle because it directly reduces the probability of production outages and security regressions.

Why this answer

Option A (Testing patches in a staging environment) is correct because a staging environment mirrors production and allows you to validate that patches install cleanly and don't break functionality before touching live systems. Option B (Reviewing vendor security advisories for patch details) is correct because advisories provide the CVE identifiers, severity ratings, affected versions, and known issues that let you prioritize and understand each patch before deployment. Option C (Performing regression testing on applications) is correct because patches can alter shared libraries, dependencies, or OS behavior, so regression testing confirms existing application functionality still works after patching.

Option D is wrong because deploying patches simultaneously to all production systems removes any rollback safety net and can cause a widespread outage if the patch is faulty. Option E is wrong because disabling security controls exposes systems to attack and is never a legitimate patch-management step.

Exam trap

The trap is the word 'before' — candidates may select deployment-speed options like simultaneous rollout, forgetting that pre-deployment validation (advisory review, staging, regression) is what the question actually asks for.

20
MCQmedium

A company is implementing a patch management process. Which of the following steps should be performed FIRST after a vendor releases a security patch for a critical vulnerability?

A.Schedule the patch for the next maintenance window
B.Test the patch in a staging environment that mirrors production
C.Deploy the patch to all production servers immediately
D.Create a patch compliance report
AnswerB

Testing the patch in a staging environment that mirrors production is the correct first step because it allows you to verify the patch against the exact operating system versions, applications, and configurations that exist in your live environment. This phase catches compatibility issues, dependency breaks, and security policy conflicts before they reach critical systems. It also lets you validate rollback procedures and measure any performance impact in an isolated setting. Confirming stability in staging builds the evidence needed to support a change management approval and a confident production rollout.

Why this answer

Patches should be tested in a staging environment to ensure they do not break critical business functions before deployment.

21
MCQmedium

A security analyst is configuring a compliance scan for a Linux server using CIS Benchmarks. The analyst must ensure the server meets Level 1 benchmarks. Which of the following is a characteristic of CIS Level 1 benchmarks?

A.They are practical and prudent, with a low impact on business functionality
B.They are only applicable to cloud environments
C.They provide specific STIG requirements for DoD systems
D.They are intended for high-security environments and may impact performance
AnswerA

CIS Level 1 profiles are designed to provide a baseline of essential security configurations that can be rapidly implemented. These recommendations are practical, prudent, and engineered to minimize any adverse impact on business operations or system performance.

Why this answer

Level 1 benchmarks are foundational and designed to have minimal impact on business operations while improving security.

22
Multi-Selectmedium

A security team is deploying a new web application and wants to ensure it follows secure configuration practices. Which THREE of the following are recommended configuration settings according to CIS benchmarks for web servers? (Select THREE.)

Select 3 answers
A.Disable directory listing
B.Use HTTP instead of HTTPS
C.Enforce HTTPS
D.Enable automatic directory browsing
E.Remove default accounts
AnswersA, C, E

Disabling directory listing on the web server prevents attackers from enumerating filenames and directory structure when no index file exists. Without this setting, requesting a directory returns a browsable list of all assets, exposing configuration backups, source code, or sensitive data. It is a core hardening step that reduces reconnaissance surface.

Why this answer

Option A (Disable directory listing) is correct because CIS benchmarks for web servers require turning off autoindex/directory browsing so that attackers cannot enumerate files and directories that lack an index page, reducing information disclosure. Option C (Enforce HTTPS) is correct because CIS guidance mandates TLS-protected transport, typically by redirecting or rejecting plain HTTP and configuring strong protocols/ciphers, to protect credentials and session data in transit. Option E (Remove default accounts) is correct because CIS benchmarks require deleting or disabling vendor-supplied default accounts and sample content, since these often ship with well-known credentials and are a common initial-access vector.

Option B (Use HTTP instead of HTTPS) does not belong because plain HTTP transmits data unencrypted and directly contradicts the requirement to enforce HTTPS. Option D (Enable automatic directory browsing) does not belong because automatic directory listing is the exact behavior that disabling directory listing is meant to prevent, and it exposes the server's file structure to unauthenticated users.

Exam trap

CS0-004 often tests whether candidates recognize that 'enable directory browsing' and 'use HTTP' are anti-patterns — the trap is selecting options that sound like configuration features but actually weaken security.

23
MCQmedium

A security analyst reviews a vulnerability scan report and identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is 'Network', attack complexity is 'Low', privileges required is 'None', user interaction is 'None', scope is 'Unchanged', and all three CIA impacts are 'High'. Which additional factor should the analyst prioritize when deciding whether to apply a patch or a compensating control?

A.The number of affected hosts
B.The EPSS score for the vulnerability
C.The OS type of the affected system
D.The vendor's patch release date
AnswerB

The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited in the wild within the next 30 days. This data-driven metric allows analysts to prioritize high-probability threats immediately and decide whether to deploy rapid patches or implement temporary compensating controls.

Why this answer

The EPSS score estimates the likelihood of exploitation in the wild, which helps prioritize remediation. CVSS alone does not indicate active exploitation.

24
MCQhard

A security analyst is reviewing a vulnerability scan report that includes a plugin output with the following CVSS v3.1 vector: AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H. Which of the following best describes the characteristics of this vulnerability?

A.Easily exploitable by an unauthenticated remote attacker
B.Requires local access, high attack complexity, high privileges, and user interaction
C.Requires physical access to exploit
D.Remotely exploitable with low complexity
AnswerB

AV:L confines the attacker to the local system, AC:H means conditions outside the attacker's control must align, PR:H demands administrative-level privileges beforehand, and UI:R requires a user to interact, matching every clause of this option exactly.

Why this answer

The vector indicates local attack vector, high complexity, high privileges required, user interaction required, changed scope, and high impact on all three CIA metrics. This suggests a local privilege escalation vulnerability.

25
MCQeasy

A security analyst is configuring a container image scanning tool. Which of the following tools is specifically designed for container image vulnerability scanning?

A.Nessus
B.Burp Suite
C.OpenVAS
D.Trivy
AnswerD

Trivy is a highly specialized, open-source vulnerability and misconfiguration scanner designed specifically for containers and other cloud-native targets. It excels at scanning container images, Git repositories, and Kubernetes configurations to detect OS package vulnerabilities and application dependency flaws directly within CI/CD pipelines.

Why this answer

Trivy is an open-source, purpose-built vulnerability scanner for container images, filesystems, and Git repositories. It scans OS packages (e.g., Alpine apk, Debian dpkg) and language-specific dependencies (npm, pip, Maven) inside an image and reports CVEs with severity ratings. Unlike general-purpose scanners, Trivy understands image layers and package manifests, making it the tool specifically designed for container image scanning in this list.

Exam trap

CS0-004 often tests the confusion between general-purpose vulnerability scanners (Nessus, OpenVAS) and specialized container image scanners (Trivy), so candidates must recognize that container scanning requires tools that understand image layers and package manifests.

How to eliminate wrong answers

Option A is wrong because Nessus is a general-purpose network and host vulnerability scanner that targets IP addresses and services, not container image layers or package manifests. Option B is wrong because Burp Suite is a web application security testing proxy focused on HTTP/HTTPS traffic and web vulnerabilities, not container image scanning. Option C is wrong because OpenVAS (now Greenbone Vulnerability Management) is a network vulnerability scanner similar to Nessus, designed for hosts and network services, not for inspecting container images.

26
MCQeasy

A vulnerability management team is prioritizing remediation of a list of vulnerabilities. They want to incorporate the likelihood of exploitation based on real-world exploit activity. Which of the following data sources should they use?

A.CVE
B.CVSS
C.KEV
D.EPSS
AnswerD

The Exploit Prediction Scoring System (EPSS) is a data-driven model that estimates the probability, ranging from 0 to 1, that a software vulnerability will be exploited in the wild within the next 30 days. By combining real-world threat intelligence with machine learning, EPSS allows security analysts to prioritize remediation efforts based on actual threat likelihood rather than theoretical severity alone.

Why this answer

The Exploit Prediction Scoring System (EPSS) uses real-world exploit data to predict the likelihood of exploitation. KEV lists known exploited vulnerabilities but is not a scoring system. CVSS and CVE are not probabilistic.

27
MCQhard

A cybersecurity analyst is configuring a vulnerability scanning policy for a mixed environment of Linux servers and Windows workstations. The analyst wants to minimize disruption to production services while ensuring comprehensive coverage. Which approach is BEST?

A.Deploy agents on all systems to perform continuous scanning
B.Scan all systems simultaneously with minimal plugin set to avoid performance issues
C.Use separate scan windows for Linux servers and Windows workstations with appropriate credentials and performance tuning
D.Schedule a single scan of all systems using default credentials and aggressive plugin settings
AnswerC

Segmenting scans by operating system allows the analyst to apply targeted credentials, which enables deep, authenticated configuration audits without generating excessive network noise. Implementing distinct scan windows and performance tuning prevents resource exhaustion on production servers and ensures that workstation scans do not disrupt business operations.

Why this answer

Using separate scan windows and credentials for each OS type minimizes disruption by scanning similar systems together and reduces load, while tailored credential profiles improve scan accuracy.

28
MCQeasy

A security analyst is using the EPSS to prioritize vulnerabilities for remediation. EPSS is designed to estimate the likelihood that a vulnerability will be exploited in the wild. Which of the following best describes how EPSS should be used in vulnerability management?

A.EPSS is only relevant for high-severity vulnerabilities with a CVSS score above 9.0.
B.EPSS replaces the need for vulnerability scanning because it predicts exploitability.
C.EPSS alone should determine the remediation order, ignoring asset criticality.
D.EPSS should be used as one of several factors in a risk-based prioritization approach.
AnswerD

Modern vulnerability management relies on risk-based prioritization, which integrates threat intelligence, asset value, and vulnerability severity. EPSS provides a dynamic, data-driven estimate of exploit probability in the wild, which helps analysts filter out thousands of vulnerabilities that are unlikely to ever be leveraged. When combined with CVSS severity and internal asset criticality, EPSS enables security teams to allocate remediation resources to the highest-risk areas first.

Why this answer

EPSS provides a probability score (0-1) that a vulnerability will be exploited in the wild within 30 days. It should be used alongside other factors like asset criticality and business context for prioritization.

29
MCQhard

A security analyst is evaluating a containerized application for vulnerabilities. The analyst runs Trivy on the container image and finds several high-severity vulnerabilities in the base image. Which of the following is the most effective remediation strategy?

A.Use a runtime security tool to monitor the container
B.Apply a host-based firewall to block exploitation attempts
C.Rebuild the image using a patched base image and redeploy
D.Disable the container until a patch is available
AnswerC

Containers are designed to be immutable, meaning that patching a running instance directly is a major operational anti-pattern. The correct remediation workflow requires updating the Dockerfile or base image to a secure version, rebuilding the container image, and redeploying it to eliminate the vulnerabilities at their source.

Why this answer

Rebuilding the container image with a patched base image addresses the root cause by eliminating vulnerable components.

30
MCQhard

A security analyst is investigating a Kubernetes cluster and finds that a container is running with securityContext.privileged: true. The container also has a hostPath mount that allows writing to the host filesystem. Which of the following best describes the primary risk of this configuration?

A.The container can only read host files, but not modify them.
B.The container can only affect other containers in the same pod, not the host.
C.The container can be used to launch a denial-of-service attack on the Kubernetes API server.
D.The container can break out of the container environment and gain root access to the host node.
AnswerD

Running a container in privileged mode grants it nearly all capabilities of the host's root user, disabling Linux namespaces and cgroups protections. When paired with a hostPath mount, an attacker can easily escape the container boundaries, access the host's sensitive system files, and execute arbitrary commands with root privileges on the underlying node.

Why this answer

A privileged container with hostPath mount can escape the container and compromise the host. The container can access host resources, potentially allowing full host compromise.

31
MCQeasy

During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of this vector indicates that the vulnerability can be exploited without any user interaction?

A.AC:L
B.AV:N
C.PR:N
D.UI:N
AnswerD

The UI:N metric stands for User Interaction: None, which explicitly confirms that the vulnerability can be exploited without any active participation or assistance from a local user. This means the attack can be executed entirely out-of-band and automatically, making it highly dangerous compared to vulnerabilities requiring social engineering or user actions like clicking a link.

Why this answer

The UI (User Interaction) metric in the CVSS vector is set to N (None), meaning no user action is required for exploitation.

32
MCQmedium

An analyst is reviewing a Nessus scan report and sees a plugin result that indicates a web application is vulnerable to SQL injection. The plugin output includes the payload used and the database error message. Which OWASP Top 10 category does this vulnerability belong to?

A.A03:2021 – Injection
B.A07:2021 – Identification and Authentication Failures
C.A09:2021 – Security Logging and Monitoring Failures
D.A01:2021 – Broken Access Control
AnswerA

SQL injection lets an attacker insert untrusted input into a database query so it is executed as code rather than data, which is the exact definition of the OWASP Injection category and explains the payload and error message in the output.

Why this answer

SQL injection is a classic injection flaw where untrusted input is interpreted as code by the database. In the OWASP Top 10 2021, SQL injection falls under A03:2021 – Injection, which encompasses SQL, NoSQL, OS command, ORM, and LDAP injection. The plugin output showing a payload and database error confirms injection.

Exam trap

The trap is misclassifying SQL injection under Broken Access Control or Authentication Failures — candidates see 'database' or 'login' and pick the wrong category, but SQLi is definitively A03:2021 – Injection.

How to eliminate wrong answers

Option B is wrong because A07:2021 – Identification and Authentication Failures covers weaknesses in authentication and session management (e.g., credential stuffing, weak passwords), not injection flaws. Option C is wrong because A09:2021 – Security Logging and Monitoring Failures covers insufficient logging, detection, and incident response, not the injection vulnerability itself. Option D is wrong because A01:2021 – Broken Access Control covers authorization flaws like IDOR and privilege escalation, not code injection.

33
MCQmedium

A security team is implementing configuration management for a set of Linux servers in a non-DoD environment. They want to apply a security baseline that provides a balanced approach between security and operational efficiency. Which of the following would be most appropriate?

A.CIS Level 1 Benchmark
B.OWASP Top 10
C.CIS Level 2 Benchmark
D.STIG for Linux
AnswerA

The CIS Level 1 Benchmark is designed to deliver a basic, essential security posture that can be rapidly implemented across systems with minimal disruption to business operations. It focuses on disabling unnecessary services, configuring basic logging, and enforcing standard access controls without breaking application functionality. This makes it the ideal starting point for general enterprise configuration management.

Why this answer

CIS Benchmarks offer two levels: Level 1 is intended for environments where usability is still a priority, and Level 2 is for high-security environments. For a non-DoD environment, CIS Level 1 is appropriate.

34
MCQmedium

A security analyst is configuring a container scanning tool to identify vulnerabilities in Docker images before deployment. Which of the following tools is specifically designed for container image vulnerability scanning?

A.Burp Suite
B.Nessus
C.Trivy
D.OpenVAS
AnswerC

Trivy scans container images for known vulnerabilities in OS packages and application dependencies, integrating into CI pipelines before deployment. This satisfies the requirement for a tool specifically designed for container image vulnerability scanning, unlike general-purpose scanners.

Why this answer

Trivy is an open-source vulnerability scanner from Aqua Security specifically designed to scan container images, filesystems, and IaC for vulnerabilities and misconfigurations. It integrates directly with Docker and CI/CD pipelines to detect CVEs in OS packages and application dependencies before deployment. This makes it the correct tool for pre-deployment container image scanning.

Exam trap

CS0-004 often tests the confusion between network vulnerability scanners (Nessus, OpenVAS) and container-specific scanners (Trivy, Clair, Anchore) — candidates pick Nessus because it is the most familiar vulnerability tool.

How to eliminate wrong answers

Option A is wrong because Burp Suite is a web application security testing tool for HTTP traffic, not container image scanning. Option B is wrong because Nessus is a general-purpose network vulnerability scanner that targets hosts and services, not container image layers. Option D is wrong because OpenVAS is an open-source network vulnerability scanner similar to Nessus, also not designed for container image analysis.

35
MCQmedium

An analyst is prioritizing vulnerabilities for remediation. The vulnerability has a high CVSS score but is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and has a low EPSS score. The affected asset is a publicly accessible web server handling sensitive customer data. Which factor should the analyst consider as most critical for prioritization?

A.The absence from the KEV catalog
B.The business context of asset criticality and exposure
C.The low EPSS score
D.The high CVSS score alone
AnswerB

Effective vulnerability management requires aligning technical severity with business impact. Prioritizing remediation based on asset criticality ensures that high-value systems containing sensitive data or supporting mission-critical operations are patched first. Additionally, evaluating network exposure, such as whether an asset is internet-facing, helps security teams address the most immediate and viable attack vectors.

Why this answer

EPSS indicates likelihood of exploitation, but business context (asset criticality and exposure) can override low EPSS if the asset is high-value and exposed. Thus, the analyst should consider the business context.

36
MCQmedium

An analyst uses Trivy to scan a container image in a CI/CD pipeline. The scan identifies a vulnerability in an open-source library included in the image. The library is not used by the application code. Which of the following actions should the analyst recommend?

A.Accept the risk because the library is not used
B.Add a web application firewall (WAF) to protect the container
C.Remove the unused library from the image
D.Patch the library to the latest version
AnswerC

Removing the unused library directly eliminates the vulnerability from the container image, adhering to the principle of least utility and minimizing the attack surface. This approach prevents potential exploitation, reduces the overall image size, and streamlines future vulnerability scanning processes. It represents the most secure and efficient remediation strategy for unused dependencies.

Why this answer

Unused components should be removed to reduce attack surface. Patching the library might be unnecessary if not used. Adding a WAF doesn't fix container image vulnerabilities.

Accepting risk may be justified but removal is better.

37
Multi-Selectmedium

A security analyst is reviewing the output of a vulnerability scan and sees a finding for a web application that uses a known vulnerable version of Apache Struts. Which TWO of the following actions should the analyst prioritize?

Select 2 answers
A.Remove the Apache Struts component entirely
B.Reboot the web server to clear memory
C.Update Apache Struts to the latest patched version
D.Disable the web application until further notice
E.Implement a WAF rule to block known exploit patterns
AnswersC, E

Upgrading Apache Struts to the latest patched version is the primary remediation because it replaces the vulnerable code with a release that includes the security fix for the specific CVE. This action directly addresses the root cause of the flaw and eliminates the attack vector for known exploit patterns. Vendor patches are thoroughly tested and are the most reliable way to restore a secure state.

Why this answer

Option C is correct because upgrading Apache Struts to the latest patched version directly remediates the underlying vulnerability (e.g., the CVE affecting that specific Struts release) and eliminates the exploitable code path. Option E is correct because a WAF rule blocking known exploit patterns (such as OGNL injection payloads targeting Struts' Content-Type or action parameters) provides immediate compensating protection while the patch is scheduled and deployed. Option A is not appropriate as a priority action because removing the Struts component entirely would likely break the web application's functionality rather than remediate it.

Option B is irrelevant because rebooting the web server does not remove or patch the vulnerable Struts library and provides no security benefit. Option D is overly disruptive; taking the application offline is a last resort and not a prioritized remediation step when patching and WAF mitigation are available.

Exam trap

CS0-004 often tests remediation prioritization, tempting candidates toward drastic actions (remove, disable, reboot) instead of the balanced patch-plus-compensating-control approach.

38
MCQmedium

A company uses Lynis for compliance scanning on Linux servers. During a scan, Lynis reports that the system has world-writable files in critical directories. Which CIS Benchmark recommendation does this finding relate to?

A.Ensure no world-writable files exist
B.Ensure system is configured to forward logs to a central server
C.Ensure permissions on /etc/shadow are configured
D.Ensure separate partition exists for /tmp
AnswerA

This finding maps directly to the CIS Benchmark recommendation that requires no world-writable files to exist in system directories, since files writable by any user create a path for unprivileged accounts or compromised processes to modify binaries, configuration files, or scripts that later run with elevated privileges.

Why this answer

CIS Benchmarks include recommendations to restrict file permissions, such as ensuring no world-writable files exist in system directories.

39
MCQeasy

Which vulnerability scanner is an open-source tool commonly used for network vulnerability scanning?

A.OpenVAS
B.Qualys
C.Nessus
D.Rapid7 InsightVM
AnswerA

OpenVAS, now maintained under the Greenbone Vulnerability Management project, is fully open-source and free to use, with a continuously updated feed of network vulnerability tests maintained by the community and Greenbone. It performs authenticated and unauthenticated network scans and is widely deployed by organizations that want scanning capability without commercial licensing costs.

Why this answer

OpenVAS is a well-known open-source vulnerability scanner.

40
Multi-Selectmedium

A company uses a patch management tool to track compliance across its server fleet. The security team needs to prioritize vulnerabilities for patching. Which THREE factors should be considered when prioritizing?

Select 3 answers
A.EPSS probability score
B.Asset criticality and exposure
C.Availability of a patch from the vendor
D.CVSS base score
E.Number of plugins that detected the vulnerability
AnswersA, B, D

The EPSS probability score is a data-driven metric from FIRST that estimates the likelihood a vulnerability will be exploited in the wild within 30 days. It is derived from real-world exploit data, CVE attributes, and threat intelligence, making it a strong indicator of active exploitation risk. As a correct prioritization input, it helps security teams focus on vulnerabilities that are most likely to be attacked, rather than just those with high theoretical severity. This is a valid and important factor for risk-based prioritization.

Why this answer

Option A (EPSS probability score) is correct because the Exploit Prediction Scoring System estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, giving a forward-looking, threat-based signal that helps rank which CVEs to patch first. Option B (Asset criticality and exposure) is correct because the same vulnerability poses very different risk depending on whether the affected server is internet-facing, holds sensitive data, or supports a critical business function, so business context must weight the technical severity. Option D (CVSS base score) is correct because it provides a standardized, vendor-neutral measure of the intrinsic severity of a vulnerability (attack vector, complexity, privileges, impact), forming the baseline technical input for prioritization.

Option C (availability of a patch from the vendor) is not a prioritization factor per se — if no patch exists, the issue is handled through compensating controls or mitigation, and patch availability does not indicate how urgent or risky the vulnerability is. Option E (number of plugins that detected the vulnerability) is irrelevant because multiple scanners reporting the same CVE is a detection artifact, not a measure of exploit likelihood or business impact.

Exam trap

CS0-004 often tests the confusion between CVSS (severity) and EPSS (exploit likelihood), or mistakenly treating patch availability as a prioritization factor.

41
MCQhard

A cloud security analyst is reviewing a misconfiguration in an AWS S3 bucket that allows public read access. The bucket contains sensitive customer data. Which of the following CIS AWS Foundations Benchmark checks would most likely identify this issue?

A.Enable default encryption for S3 buckets
B.Enable S3 bucket logging
C.Enable versioning on S3 buckets
D.Ensure S3 buckets do not allow public read access
AnswerD

This CIS control checks bucket ACLs and bucket policies for statements granting access to 'Everyone' or 'AuthenticatedUsers' groups, which is precisely the misconfiguration exposing sensitive customer data, making it the check that flags and drives remediation of the finding.

Why this answer

CIS AWS Foundations Benchmark includes a control for ensuring S3 buckets do not allow public read access. The control is typically '1.5 Ensure S3 bucket policy restricts public read access'. 'Enable S3 bucket logging' is about logging, not access. 'Enable default encryption' is about encryption. 'Enable versioning' is about data protection.

42
MCQmedium

A security analyst is configuring a vulnerability scan using OpenVAS. The scan should identify missing patches on Windows servers. Which of the following scan types should the analyst select?

A.Credentialed scan
B.Passive scan
C.Unauthenticated scan
D.Port scan
AnswerA

Credentialed scans utilize valid administrative or user credentials to authenticate directly to the target system. This allows the scanner to query the local registry, inspect the file system, and query package managers to verify the exact patch levels and configuration settings. Consequently, this approach provides the most accurate assessment with minimal false positives.

Why this answer

OpenVAS uses authenticated scans to check for missing patches. Unauthenticated scans only detect open ports and services. A credentialed scan with valid credentials allows checking patch levels.

43
Multi-Selectmedium

A security analyst is using OpenVAS to scan a network. The scan identifies several vulnerabilities. Which TWO of the following are valid components of a CVSS v3.1 base score? (Select the two correct answers.)

Select 2 answers
A.Exploitability (E)
B.Confidence (C)
C.Remediation Level (RL)
D.Scope (S)
E.Attack Vector (AV)
AnswersD, E

Scope (S) is a correct base metric in CVSS v3.1, measuring whether a vulnerability in one vulnerable component can impact resources beyond its security scope. A changed scope indicates that exploitation may affect other components, increasing the overall severity. OpenVAS includes Scope in the base vector, so it is a valid base metric.

Why this answer

Scope (S) is a valid CVSS v3.1 base metric that indicates whether a vulnerability can affect resources beyond the security scope of the vulnerable component, with values Unchanged (U) or Changed (C). Attack Vector (AV) is also a valid base metric describing the context in which the vulnerability is exploitable, with values Network (N), Adjacent (A), Local (L), or Physical (P). Both belong to the Base metric group, which also includes Attack Complexity (AC), Privileges Required (PR), User Interaction (UI), Confidentiality (C), Integrity (I), and Availability (A).

Exploitability (E), Confidence (C), and Remediation Level (RL) are not base metrics: E and RL are Temporal metrics in CVSS v3.1, and Confidence is a metric from the older CVSS v2 environmental scoring, not part of CVSS v3.1 base scoring.

Exam trap

CS0-004 often tests the boundary between CVSS metric groups — candidates confuse Temporal metrics like Exploitability and Remediation Level with Base metrics.

44
MCQmedium

A security analyst is reviewing a Kubernetes cluster configuration. Which of the following misconfigurations poses the MOST severe security risk?

A.Using hostPath mounts with read-only access
B.Using ConfigMaps for non-sensitive data
C.Privileged containers with unrestricted host access
D.Running containers as non-root user
AnswerC

A privileged container runs with nearly all Linux capabilities enabled and direct access to host devices, meaning a compromised container can mount the host filesystem, load kernel modules, and effectively break out of container isolation entirely, giving an attacker root-equivalent control over the underlying node.

Why this answer

Privileged containers bypass all security restrictions and can access the host system, posing the most severe risk.

45
Multi-Selectmedium

A security analyst is prioritizing vulnerabilities for a critical internet-facing application server. The analyst has CVSS scores, EPSS scores, and access to the CISA KEV catalog. Which TWO factors should the analyst consider as the most important for determining remediation priority? (Select TWO)

Select 2 answers
A.Asset criticality and business context
B.CVSS base score
C.Number of plugins detecting the vulnerability
D.EPSS score
E.CISA Known Exploited Vulnerabilities (KEV) catalog
AnswersA, E

Asset criticality and business context are central to vulnerability prioritization because they determine the potential impact on operations, data confidentiality, and compliance. A critical internet-facing server, for example, represents a higher risk to the organization if compromised, even when the vulnerability's severity is moderate. Contextual factors such as exposure, sensitive data, and required availability turn a generic technical finding into a prioritized business risk.

Why this answer

Option A (Asset criticality and business context) is correct because remediation priority must reflect the value and exposure of the affected system; a critical internet-facing application server supporting key business functions warrants higher priority than a low-value internal host, regardless of raw severity scores. Option E (CISA Known Exploited Vulnerabilities (KEV) catalog) is correct because KEV lists vulnerabilities known to be actively exploited in the wild, which is the strongest evidence of immediate real-world risk and should drive urgent remediation. CVSS base score (B) measures intrinsic technical severity but not exploit likelihood or business impact, so it is only one input and not the top priority factor.

EPSS score (D) estimates the probability of exploitation but does not capture asset importance or confirmed exploitation like KEV does. The number of plugins detecting the vulnerability (C) is a scanner artifact and has no bearing on actual risk or remediation priority.

Exam trap

CS0-004 often tests the misconception that CVSS base score alone is sufficient for prioritization, ignoring the need to incorporate asset criticality and active exploitation evidence like KEV.

46
MCQeasy

A security analyst is reviewing vulnerability scan results and notices that a critical vulnerability on a web server has a CVSS v3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of the CVSS vector indicates that the vulnerability can be exploited from a remote network?

A.PR:N
B.AV:N
C.AC:L
D.UI:N
AnswerB

The Attack Vector (AV) metric represents the context in which vulnerability exploitation is possible. A value of AV:N (Network) explicitly indicates that the vulnerability is exploitable remotely over the network, meaning the attacker does not need local, physical, or adjacent network access to compromise the target.

Why this answer

AV stands for Attack Vector. AV:N means the vulnerability is exploitable over a network, indicating remote exploitation.

47
MCQhard

A security team is using EPSS scores and CISA KEV catalog to prioritize vulnerabilities. Which combination of factors would indicate the HIGHEST priority for remediation?

A.Medium CVSS score and high asset criticality
B.High EPSS score and presence in KEV catalog
C.High CVSS score and low EPSS score
D.Low CVSS score and presence in KEV catalog
AnswerB

This combination represents the highest remediation priority because the CISA KEV catalog confirms the vulnerability is currently being exploited in the wild, while a high EPSS score mathematically predicts a high probability of imminent exploitation. Leveraging both threat-centric metrics allows security analysts to transition from theoretical severity to active risk-based patching.

Why this answer

CISA KEV catalog contains vulnerabilities known to be exploited in the wild, and a high EPSS score indicates a high probability of exploitation. Together, they indicate the highest priority.

48
MCQhard

A security analyst is using Nessus to scan a network. The scan completes and reports a vulnerability with a CVSS v3.1 base score of 5.3 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerability is a low-information disclosure issue that reveals the server's internal IP address in HTTP headers. The asset is a public-facing web server. Which of the following best describes the risk level and appropriate response?

A.Low risk; no action needed because internal IP disclosure is not a vulnerability.
B.Critical risk because the server is public-facing; immediate patching is required.
C.Medium risk; schedule a configuration change to remove the header during the next maintenance window.
D.High risk due to public exposure; apply an emergency patch to hide the header.
AnswerC

Disclosing internal IP addresses in HTTP headers is typically classified as a medium-risk vulnerability that facilitates external reconnaissance. Remediation involves modifying the web server configuration to prevent the disclosure, which is a non-emergency change that should be scheduled during a standard maintenance window to avoid service disruption.

Why this answer

The CVSS score is 5.3 (Medium) with low impact on confidentiality and no impact on integrity or availability. Although it is a public-facing server, the risk is low because the information disclosed is minimal (internal IP), which may already be known or easily guessable. The appropriate response is to schedule remediation during normal maintenance, not an emergency.

49
MCQmedium

A security analyst is reviewing the results of a vulnerability scan and notices that several vulnerabilities have high CVSS scores but low EPSS scores. The analyst also cross-references the CISA Known Exploited Vulnerabilities (KEV) catalog and finds that none of these vulnerabilities are listed. Which approach should the analyst take when prioritizing remediation?

A.Remediate vulnerabilities with high CVSS scores only if they are internet-facing.
B.Prioritize based on EPSS scores and KEV status, but also consider business context.
C.Remediate only vulnerabilities found in the KEV catalog.
D.Remediate all vulnerabilities with CVSS scores above 9.0 immediately.
AnswerB

Combining the Exploit Prediction Scoring System (EPSS) and CISA's Known Exploited Vulnerabilities (KEV) catalog allows analysts to focus on threats with active, real-world exploitation activity. Integrating business context ensures that remediation efforts are directed toward high-value assets that directly impact organizational operations. This risk-based approach optimizes resource allocation and significantly reduces actual organizational exposure compared to relying solely on static severity scores.

Why this answer

EPSS predicts the likelihood of exploitation, and KEV lists vulnerabilities known to be exploited in the wild. High CVSS but low EPSS and not in KEV suggests the vulnerability may be severe but unlikely to be exploited currently. However, business context such as asset criticality and exposure should be considered; if the asset is critical and exposed, remediation should still be prioritized despite low exploitation likelihood.

50
Multi-Selectmedium

A security analyst is prioritizing vulnerabilities discovered during a scan. Which TWO factors should the analyst consider as part of business context to determine remediation priority? (Select TWO.)

Select 2 answers
A.Asset exposure
B.CVSS base score
C.Patch availability
D.Exploit availability
E.Asset criticality
AnswersA, E

Exposure determines the likelihood of attack, considering whether the asset is internet-facing or reachable by potential adversaries. It directly influences the probability of exploitation, making it a fundamental factor in prioritizing vulnerabilities. Without exposure, even a critical vulnerability on an internal system poses less immediate risk. Therefore, asset exposure is the primary determinant for prioritizing remediation efforts.

Why this answer

Asset exposure (A) is a business-context factor because it describes whether the vulnerable asset is reachable from untrusted networks such as the internet, DMZ, or internal segments, directly affecting the likelihood of exploitation and thus remediation priority. Asset criticality (E) is also business context because it reflects the asset's role and value to the organization—such as processing regulated data, supporting revenue-generating services, or being a domain controller—which determines the business impact if compromised. In contrast, CVSS base score (B) is a technical severity metric derived from intrinsic vulnerability characteristics and does not by itself capture business context.

Patch availability (C) is a remediation logistics factor, and exploit availability (D) is a threat-intelligence factor; neither is a business-context input for prioritization.

Exam trap

CS0-004 often tests the distinction between technical severity metrics (CVSS, EPSS, exploit availability) and business-context factors (asset exposure, asset criticality) — candidates frequently pick CVSS because it 'sounds like' a prioritization input.

51
MCQeasy

During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is network, attack complexity is low, privileges required are none, user interaction is none, and the impact to confidentiality, integrity, and availability is high. Which CVSS vector string represents this vulnerability?

A.CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
B.CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
C.CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
D.CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AnswerA

Every metric matches the scenario exactly: AV:N reflects remote network exploitability, AC:L means no special conditions are needed, PR:N and UI:N confirm no authentication or victim action is required, and C:H/I:H/A:H capture the total loss of confidentiality, integrity, and availability, which together drive the 9.8 critical base score.

Why this answer

The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a vulnerability with network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and high impact to confidentiality, integrity, and availability. This matches the description and yields a base score of 9.8 (Critical).

Exam trap

CS0-004 often tests the ability to map a description to the correct CVSS vector; candidates may confuse AC:L with AC:H or PR:N with PR:L, so they must read the description carefully.

How to eliminate wrong answers

Option B is wrong because it has AC:H (High attack complexity), which would lower the score and does not match the 'low' complexity described. Option C is wrong because it has PR:L (Low privileges required), but the description states 'privileges required are none'. Option D is wrong because it has AV:A (Adjacent network), but the description states 'attack vector is network'.

52
MCQmedium

A security analyst is reviewing a vulnerability scan report and notices a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and the scope impact?

A.Attack vector: Network; Scope: Unchanged
B.Attack vector: Network; Scope: Changed
C.Attack vector: Local; Scope: Changed
D.Attack vector: Adjacent; Scope: Unchanged
AnswerA

Correct. AV:N indicates the vulnerability is exploitable remotely over a network without requiring physical or adjacent access, and S:U means the exploited component's impact stays confined within its own security scope rather than affecting resources managed by a different authority.

Why this answer

The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H decodes as Attack Vector: Network (AV:N) and Scope: Unchanged (S:U). AV:N means the vulnerability is exploitable remotely over a network, and S:U means a successful exploit affects only the vulnerable component's security authority, not other components. The 9.8 base score is consistent with a network-exploitable, no-privilege, no-interaction, high-impact vulnerability with unchanged scope.

Exam trap

CS0-004 often tests CVSS vector decoding — candidates confuse AV:N with AV:A or misread S:U as S:C, especially when the high 9.8 score suggests 'changed scope' intuitively.

How to eliminate wrong answers

Option B is wrong because the vector contains S:U (Scope: Unchanged), not S:C — a changed scope would require S:C and typically a different impact profile. Option C is wrong because AV:L (Local) would require local access, but the vector specifies AV:N (Network); also scope is Unchanged, not Changed. Option D is wrong because AV:A (Adjacent) would mean the attacker must be on the same logical network segment, but the vector specifies AV:N; scope is correctly Unchanged but the attack vector is misread.

53
MCQhard

A security analyst is reviewing a vulnerability scan of a Kubernetes cluster. The scan reports that a container is running with privileged mode enabled. Which CIS Kubernetes Benchmark recommendation does this violation relate to?

A.Ensure that containers are not running with privileged access
B.Ensure that the cluster-admin role is not used
C.Ensure that the API server is not exposed to the internet
D.Ensure that etcd is configured with TLS
AnswerA

Running containers with privileged access essentially grants them the same capabilities as the host root user, bypassing container isolation boundaries. CIS Kubernetes benchmarks strongly recommend disabling privileged containers to prevent container breakout attacks, where an attacker compromises a container and escalates privileges to compromise the underlying node.

Why this answer

The CIS Kubernetes Benchmark includes a recommendation to avoid running containers with privileged access, as it increases security risks. This is a common misconfiguration.

54
MCQmedium

During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch is intended to fix a remote code execution vulnerability in a widely used application. What is the MOST important step before deploying to production?

A.Check the patch's CVSS score
B.Verify the patch's digital signature
C.Automatically deploy to all production servers immediately
D.Perform regression testing to ensure no breakage
AnswerD

During the testing phase of patch management, regression testing is essential to confirm that the newly applied software update does not break or degrade existing system functionalities, APIs, or custom integrations. This systematic validation ensures that while the security vulnerability is successfully mitigated, the operational stability of the application or operating system remains fully intact before deployment.

Why this answer

Regression testing is the most important step because a patch that fixes a remote code execution vulnerability can still introduce functional regressions or break dependent applications in production. Testing in staging validates that the patch resolves the vulnerability without breaking existing functionality, integrations, or workflows. This aligns with change management best practices where validation precedes production deployment.

Exam trap

CS0-004 often tests the distinction between vulnerability severity (CVSS) and patch safety, tricking candidates into choosing the 'most urgent' action rather than the 'most important' validation step.

How to eliminate wrong answers

Option A is wrong because checking the CVSS score only tells you the severity of the vulnerability being patched, not whether the patch itself is safe to deploy. Option B is wrong because verifying the digital signature confirms authenticity and integrity of the patch package, but does not validate that the patch will not break production systems. Option C is wrong because automatically deploying to all production servers without testing violates change management and can cause widespread outages if the patch is faulty.

55
MCQmedium

An organization uses a DAST tool to test a web application for vulnerabilities. The tool sends specially crafted requests and analyzes responses. Which of the following vulnerabilities is a DAST tool most effective at identifying?

A.Outdated library versions in code
B.Insecure cryptographic algorithms in code
C.Hardcoded credentials in source code
D.SQL injection
AnswerD

SQL injection is a runtime vulnerability that DAST tools are highly effective at identifying. By actively injecting malicious payloads into input fields, query parameters, and headers, the DAST scanner analyzes the application's HTTP responses and database error messages to confirm the vulnerability. This black-box testing closely mimics the behavior of an external attacker.

Why this answer

DAST tools are effective at finding runtime vulnerabilities like SQL injection, XSS, and other injection flaws by simulating attacks on the running application.

56
MCQmedium

A security analyst is using OpenSCAP to perform a compliance scan against a set of RHEL servers. The analyst wants to ensure the servers comply with the CIS Benchmark Level 1 for Red Hat Enterprise Linux. What does Level 1 typically indicate?

A.A custom profile defined by the organization
B.A set of security controls that are considered best practices with minimal impact on functionality
C.The most secure configuration possible
D.Configuration settings that are required for DoD environments
AnswerB

The CIS Level 1 profile is specifically designed to provide a basic, highly effective reduction of an organization's attack surface while minimizing disruption to business operations and system utility. These consensus-based recommendations can be rapidly implemented across an enterprise without causing significant compatibility issues or administrative overhead.

Why this answer

CIS Benchmarks define Level 1 as basic security requirements that can be implemented with minimal impact on functionality, while Level 2 includes more stringent controls.

57
MCQmedium

A vulnerability management team is evaluating whether to apply a patch immediately or implement a compensating control. The patch is for a vulnerability in a legacy system that cannot be taken offline during business hours. The compensating control would involve restricting network access to the system. Which decision is MOST appropriate?

A.Ignore the vulnerability since it affects a legacy system
B.Remove the system from the network
C.Implement a compensating control and schedule patching during a maintenance window
D.Apply the patch immediately despite the outage risk
AnswerC

This approach aligns with best-practice vulnerability management by balancing the need for security against operational availability. A compensating control, such as an internal network access control list (ACL) or an updated intrusion prevention system (IPS) signature, reduces the likelihood or impact of exploitation until the patch can be installed during a scheduled maintenance window. This ensures that the system remains functional and that the patch is tested and deployed in a controlled manner, minimizing downtime and the risk of unexpected failures. It is the correct decision because it addresses the vulnerability without disproportionate disruption to the business.

Why this answer

If the system cannot be patched immediately, implementing a compensating control (network restriction) reduces risk while waiting for a maintenance window.

58
MCQeasy

An organization uses CIS Benchmarks to secure its Linux servers. The security team applies Level 1 benchmarks. Which of the following best describes Level 1 CIS benchmarks?

A.Advanced security settings that may reduce functionality
B.Required for all internet-facing systems
C.Basic security configurations with minimal operational impact
D.Only applicable to DoD environments
AnswerC

CIS Level 1 benchmarks are meticulously designed to establish a foundational security posture across various systems without significantly disrupting business operations or demanding extensive resources. These basic security configurations focus on essential hardening steps that are broadly applicable and easy to implement, ensuring a robust security baseline can be achieved with minimal risk of system instability or performance degradation. This approach makes them highly practical for widespread adoption.

Why this answer

CIS Benchmarks Level 1 profiles consist of basic security configurations that are essential for any system and have minimal impact on functionality. They are considered the minimum baseline and are safe to apply to most systems without disrupting operations.

Exam trap

CS0-004 often tests the distinction between Level 1 and Level 2 CIS Benchmarks, where candidates might confuse Level 1 with advanced settings or think it is only for specific environments.

How to eliminate wrong answers

Option A is wrong because advanced security settings that may reduce functionality are characteristic of Level 2 benchmarks, not Level 1. Option B is wrong because while Level 1 is recommended for all systems, it is not specifically 'required' for internet-facing systems; that is a misinterpretation. Option D is wrong because CIS Benchmarks are not only applicable to DoD environments; they are widely used across industries and government agencies, but not exclusively DoD.

59
MCQmedium

A security analyst is prioritizing vulnerabilities for remediation. One vulnerability has a CVSS v3.1 score of 7.5, an EPSS score of 0.02, and is not in the CISA KEV catalog. Another vulnerability has a CVSS score of 5.0, an EPSS score of 0.85, and is listed in the KEV catalog. Which vulnerability should be prioritized FIRST?

A.The vulnerability with CVSS 7.5
B.Both should be prioritized equally
C.Neither should be prioritized until a full risk assessment is done
D.The vulnerability with CVSS 5.0
AnswerD

The vulnerability with a CVSS score of 5.0 should be prioritized because its high EPSS score and inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog indicate active, real-world exploitation. Remediation efforts must focus on vulnerabilities with proven threat actor activity, as they represent an immediate entry point, regardless of a moderate base severity score.

Why this answer

EPSS and KEV catalog provide real-world exploit intelligence. The vulnerability with high EPSS and KEV is more likely to be exploited, so it should be prioritized despite lower CVSS.

60
MCQeasy

Which tool is specifically designed to check Linux systems for compliance with security best practices and can be used for configuration auditing?

A.Burp Suite
B.OpenVAS
C.Nessus
D.Lynis
AnswerD

Lynis is an open-source, battle-tested security auditing tool specifically designed for Unix-like operating systems, including Linux and macOS. It runs locally on the host to perform deep scans of system configurations, bootloaders, kernel parameters, and installed packages, providing actionable hardening recommendations to improve overall system defense.

Why this answer

Lynis is a security auditing tool for Linux/Unix systems that performs compliance checks and configuration reviews.

61
MCQeasy

Which of the following tools is specifically designed for compliance scanning against security benchmarks on Linux systems?

A.OpenVAS
B.Nessus
C.Lynis
D.Qualys
AnswerC

Lynis is an open-source, host-based security auditing tool specifically engineered for Unix, Linux, and macOS systems. It conducts deep local scans to evaluate system hardening, detect configuration flaws, and verify compliance with frameworks like PCI-DSS and ISO 27001. Unlike network scanners, it runs directly on the target operating system to inspect local configuration files and system parameters.

Why this answer

Lynis is an open-source security auditing tool specifically designed for Linux systems, performing compliance scans against benchmarks like CIS, HIPAA, and PCI-DSS. It checks system hardening, kernel parameters, file permissions, and installed software. OpenVAS, Nessus, and Qualys are general vulnerability scanners, not Linux-specific compliance benchmark tools.

Exam trap

CS0-004 often tests confusion between vulnerability scanners (Nessus, OpenVAS, Qualys) and compliance/hardening tools (Lynis), where candidates pick a well-known scanner instead of the Linux-specific benchmark tool.

How to eliminate wrong answers

Option A is wrong because OpenVAS is a general-purpose vulnerability scanner (part of Greenbone) that scans networks and hosts for CVEs, not a Linux compliance benchmark tool. Option B is wrong because Nessus is a commercial vulnerability scanner for broad vulnerability assessment, not specifically for Linux compliance benchmarks. Option D is wrong because Qualys is a cloud-based vulnerability management and compliance platform, broader than Linux-specific benchmark scanning.

62
MCQmedium

An organization wants to prioritize vulnerabilities based on the likelihood of exploitation. Which of the following sources provides a data-driven probability score for exploitation?

A.CVSS v3.1
B.EPSS
C.CIS Benchmarks
D.OWASP Top 10
AnswerB

The Exploit Prediction Scoring System (EPSS) is a data-driven model that estimates the probability that a specific vulnerability will be exploited in the wild within the next 30 days. By integrating real-time threat intelligence and historical exploit data, EPSS allows security analysts to prioritize remediation efforts based on actual threat activity rather than theoretical severity alone.

Why this answer

EPSS uses real-world data to predict the probability of exploitation, aiding in prioritization.

63
MCQeasy

During a vulnerability assessment, a security analyst uses a tool that identifies missing patches and misconfigurations based on CIS Benchmarks. Which of the following tools is specifically designed for compliance scanning against CIS benchmarks?

A.OpenSCAP
B.Qualys
C.Nessus
D.OpenVAS
AnswerA

OpenSCAP is an open-source security compliance tool designed specifically to audit systems against standardized security baselines, such as the Center for Internet Security (CIS) benchmarks and DISA STIGs. It utilizes the Security Content Automation Protocol (SCAP) to automate configuration compliance checking and vulnerability assessment, making it the ideal choice for verifying adherence to specific security frameworks.

Why this answer

OpenSCAP is an open-source implementation of the Security Content Automation Protocol (SCAP) that natively consumes SCAP content, including CIS Benchmarks delivered as XCCDF/OVAL datastreams. It is specifically designed for compliance scanning and remediation against benchmarks like CIS, PCI DSS, and STIG. Running 'oscap xccdf eval' against a CIS benchmark profile produces a compliance report mapped to the benchmark's controls.

Exam trap

CS0-004 often tests whether candidates can distinguish SCAP-native compliance tools from general vulnerability scanners — the trap is picking a well-known commercial scanner like Nessus or Qualys when the question specifically asks for CIS benchmark compliance scanning.

How to eliminate wrong answers

Option B is wrong because Qualys is a commercial vulnerability management platform that can import CIS content but is not specifically designed for CIS benchmark compliance scanning — its primary focus is vulnerability detection and asset management. Option C is wrong because Nessus is a general-purpose vulnerability scanner; while Tenable provides CIS audit files, Nessus itself is not a SCAP-native compliance engine. Option D is wrong because OpenVAS (Greenbone) is an open-source vulnerability scanner focused on network vulnerability detection, not SCAP/CIS benchmark compliance evaluation.

64
MCQeasy

A security analyst is reviewing the results of a vulnerability scan. The analyst sees a plugin output that includes the CVSS vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. What is the base score of this vulnerability?

A.6.5
B.9.8
C.10.0
D.7.5
AnswerB

The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a worst-case scenario where an unauthenticated remote attacker can fully compromise confidentiality, integrity, and availability without user interaction. Because the Scope is Unchanged (S:U), the mathematical formula caps the maximum possible base score at 9.8 rather than 10.0.

Why this answer

The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a network-exploitable vulnerability with low attack complexity, no privileges or user interaction required, unchanged scope, and high impact to confidentiality, integrity, and availability. This combination yields a base score of 9.8 (Critical), the maximum for an unchanged-scope vulnerability.

Exam trap

CS0-004 often tests the Scope metric — candidates see all-High impacts and pick 10.0, forgetting that 10.0 requires S:C (Changed), while S:U caps the score at 9.8.

How to eliminate wrong answers

Option A (6.5) is wrong because it corresponds to a medium-severity vector such as AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, which requires privileges or has partial impact — not the all-high, no-prerequisite vector shown. Option C (10.0) is wrong because a 10.0 requires Scope:Changed (S:C) in addition to all-high impacts; the vector here has S:U (Unchanged), capping the score at 9.8. Option D (7.5) is wrong because it corresponds to a high-severity but less severe vector, typically with network access but partial impact or required user interaction, not the fully unauthenticated all-high profile shown.

65
MCQmedium

A security team is implementing CIS Benchmarks for a Linux server. They need to choose between Level 1 and Level 2 benchmarks. Which of the following best describes Level 1 benchmarks?

A.They are basic security settings that can be implemented with minimal disruption
B.They are mandatory for compliance with DoD STIGs
C.They are the most restrictive settings, suitable for high-security environments
D.They include advanced settings that require extensive testing
AnswerA

Level 1 controls, such as disabling unused filesystems or setting basic password policies, are designed to reduce the attack surface without breaking common applications, making them suitable as a default baseline for nearly any server.

Why this answer

CIS Level 1 benchmarks are defined as basic, essential security settings that can be applied with minimal disruption to functionality and are intended for all systems. They represent a practical baseline that most organizations can implement without extensive testing or performance impact, making them suitable as a starting point for hardening. This matches option A's description of basic settings with minimal disruption.

Exam trap

CS0-004 often tests the confusion between Level 1 and Level 2, where candidates incorrectly associate Level 1 with high-security or mandatory compliance settings rather than its true role as a minimal-disruption baseline.

How to eliminate wrong answers

Option B is wrong because CIS Benchmarks are not mandatory for DoD STIG compliance; STIGs are separate DoD-specific hardening guides, and while they may overlap, CIS Level 1 is not a STIG requirement. Option C is wrong because Level 2, not Level 1, contains the most restrictive settings intended for high-security environments. Option D is wrong because Level 2 benchmarks include advanced settings that require extensive testing and may impact functionality; Level 1 is specifically designed to avoid that.

66
MCQhard

During a web application penetration test using Burp Suite, a security analyst identifies that an API endpoint accepts a URL parameter that is used to fetch data from an external resource. The application does not validate or sanitize the parameter. This is most likely vulnerable to which attack?

A.SQL injection
B.Server-Side Request Forgery (SSRF)
C.Cross-site scripting (XSS)
D.XML External Entity (XXE)
AnswerB

Because the unvalidated URL parameter is used server-side to fetch a resource, an attacker can substitute internal addresses, cloud metadata endpoints, or restricted URLs, forcing the server itself to issue requests it controls, which is the defining behavior of Server-Side Request Forgery.

Why this answer

When an application takes a user-supplied URL parameter and fetches content from it without validation, the server can be tricked into making requests to internal or external resources on the attacker's behalf. This is the classic definition of Server-Side Request Forgery (SSRF). The lack of validation or sanitization of the URL parameter is the key indicator, allowing attackers to reach internal metadata endpoints (e.g., 169.254.169.254) or internal services.

Exam trap

CS0-004 often tests the confusion between SSRF and XXE or SQLi — candidates must recognize that a URL parameter used for server-side fetching without validation is the signature of SSRF, not injection into a database or XML parser.

How to eliminate wrong answers

Option A is wrong because SQL injection involves injecting SQL syntax into database queries, not fetching external resources via URL parameters. Option C is wrong because XSS executes script in a victim's browser, whereas SSRF abuses the server's ability to make outbound requests. Option D is wrong because XXE exploits XML parsers that process external entities, which requires XML input and a vulnerable parser — not a URL fetch parameter.

67
MCQeasy

Which of the following vulnerability lifecycle phases involves verifying that a remediation has been successfully applied and that the vulnerability no longer exists?

A.Discovery
B.Prioritization
C.Remediation
D.Verification
AnswerD

Verification is the closing phase of the lifecycle, where the analyst re-scans or otherwise re-tests the previously vulnerable asset to confirm the remediation was applied correctly and the vulnerability no longer exists, closing the loop before the finding can be marked resolved in the tracking system.

Why this answer

Verification is the phase where after remediation, the system is rescanned or checked to confirm the vulnerability is mitigated.

68
Multi-Selectmedium

A security analyst is evaluating a Kubernetes cluster for misconfigurations. Which TWO of the following are common Kubernetes misconfigurations that increase security risk? (Select the two best answers.)

Select 2 answers
A.Running containers as non-root user
B.Using hostPath mounts
C.Using privileged containers
D.Enabling Role-Based Access Control (RBAC)
E.Implementing network policies to restrict traffic
AnswersB, C

hostPath mounts bind a node's filesystem directory into a pod, breaking container isolation. A compromised pod can then read or write node files, including credentials and the kubelet configuration, escalating beyond its namespace and undermining the cluster's security boundary.

Why this answer

Option B (Using hostPath mounts) is correct because a hostPath volume mounts a file or directory directly from the node's filesystem into the pod, allowing a compromised container to read or write sensitive node paths such as /etc, /var/run/docker.sock, or kubelet credentials, which can lead to node takeover or cluster compromise. Option C (Using privileged containers) is correct because a privileged container runs with essentially all Linux capabilities and full access to host devices and kernel interfaces (equivalent to --privileged), disabling isolation and enabling container escape and host compromise. Option A is not a misconfiguration but a security best practice, since running as non-root reduces privilege.

Option D is not a misconfiguration because enabling RBAC is a recommended access-control hardening measure. Option E is not a misconfiguration because network policies that restrict pod traffic reduce lateral movement and are a security best practice.

69
MCQmedium

A company uses a configuration management tool to enforce CIS Benchmarks on its servers. The security team wants to apply Level 1 benchmarks to all servers to achieve a baseline security posture. Which of the following best describes the difference between CIS Level 1 and Level 2 benchmarks?

A.Level 1 benchmarks are for Linux systems, while Level 2 benchmarks are for Windows systems.
B.Level 1 benchmarks are basic security measures that do not impact system performance, while Level 2 benchmarks are more restrictive and may affect performance or usability.
C.Level 1 benchmarks are for servers, while Level 2 benchmarks are for workstations.
D.Level 1 benchmarks are mandatory, while Level 2 benchmarks are optional.
AnswerB

CIS Benchmarks define Level 1 as the core set of security configurations that can be implemented without significantly degrading system functionality or causing incompatibility, making them suitable for most environments. Level 2 extends these settings with more aggressive hardening, such as disabling legacy protocols or tightening file permissions, which may reduce performance, break existing workflows, or require additional operational overhead. This performance-versus-restriction trade-off is the intended distinction.

Why this answer

CIS Benchmarks define Level 1 as essential, basic security settings that can be applied broadly with minimal impact on functionality or performance, making them suitable as a universal baseline. Level 2 settings are defense-in-depth measures intended for high-security environments; they are more restrictive and may degrade performance or break usability (e.g., disabling legacy protocols or enforcing strict password policies). The question's goal of a baseline posture maps directly to Level 1.

Exam trap

The trap is conflating the Level 1/Level 2 distinction with OS or device-type categories; candidates who haven't read the CIS documentation assume the levels map to platform tiers.

How to eliminate wrong answers

Option A is wrong because CIS Benchmarks are OS- and application-specific (there are separate benchmarks for Linux distros, Windows Server, macOS, etc.), and both Level 1 and Level 2 exist within each benchmark — the levels are not split by operating system. Option C is wrong because the Level 1/Level 2 distinction is about security strictness, not device role; both levels apply to servers and workstations within their respective benchmarks. Option D is wrong because neither level is 'mandatory' in a regulatory sense — they are recommendations, and organizations choose which profile to apply based on risk tolerance and operational constraints.

70
MCQmedium

During a web application security assessment using OWASP ZAP, a tester identifies that the application reflects user input in HTTP responses without proper encoding. Which OWASP Top 10 vulnerability category does this finding most likely belong to?

A.Broken Access Control
B.Cryptographic Failures
C.Security Misconfiguration
D.Injection
AnswerD

Injection occurs when untrusted user input is directly interpreted as code by an interpreter. Cross-Site Scripting (XSS) is a specific type of injection vulnerability where malicious scripts are injected into benign and trusted websites. During an OWASP ZAP assessment, the tool identifies this by injecting payload strings and verifying if they execute within the context of the victim's browser session.

Why this answer

Reflected user input in responses without encoding is a classic sign of Cross-Site Scripting (XSS), which falls under injection in OWASP Top 10 (though XSS is specifically listed as a separate category in some versions, but in 2021 it is under injection).

71
MCQmedium

An organization is implementing a patch management process for servers. Which of the following is a crucial step that should be performed before deploying patches to production servers?

A.Immediately apply the patch to all systems to minimize exposure
B.Review the CVSS score to decide if the patch is necessary
C.Verify patch compliance by checking the vendor's advisory
D.Test the patch in a staging environment that closely mirrors production
AnswerD

Validating the patch in a dedicated staging environment that replicates production configurations allows administrators to identify potential software conflicts, performance degradation, or deployment failures. This isolated testing ensures that the update can be safely applied to production systems without disrupting critical business operations.

Why this answer

Before deploying patches to production servers, the critical step is to test the patch in a staging environment that closely mirrors production, because patches can introduce regressions, break application compatibility, or cause unexpected downtime. Testing in staging validates that the patch works correctly with the organization's specific configurations, dependencies, and workloads before it affects live systems. This is a foundational principle of change management and patch management frameworks.

Exam trap

The trap is the urgency bias — candidates feel pressure to 'patch immediately to reduce exposure' and pick option A, forgetting that untested patches can cause outages that are just as damaging as the vulnerability itself. The exam tests whether you prioritize controlled change management over reflexive urgency.

How to eliminate wrong answers

Option A is wrong because immediately applying patches to all systems without testing is reckless — it maximizes the risk of widespread outages or application failures if the patch is faulty or incompatible, violating change-management best practices. Option B is wrong because reviewing the CVSS score helps prioritize which patches to apply first, but it does not replace the need to test the patch before production deployment — CVSS measures severity, not compatibility. Option C is wrong because verifying patch compliance by checking the vendor's advisory confirms the patch exists and is legitimate, but it does not validate that the patch will function correctly in the organization's environment.

72
MCQeasy

Which of the following is the BEST description of configuration drift?

A.A planned change to a system's configuration
B.The process of reverting a system to its baseline configuration
C.The gradual deviation of a system's configuration from the intended baseline
D.A vulnerability that is patched and then reappears
AnswerC

Configuration drift is the gradual and often unnoticed deviation of a system's current configuration from its intended, documented baseline. It results from incremental changes such as manual edits, emergency fixes, unpatchable workarounds, or inconsistent patch deployments that accumulate over time without change-control approval. This divergence can lead to security weaknesses, compliance violations, and unpredictable behavior, making it a central concern for configuration management.

Why this answer

Configuration drift refers to the gradual change in system configurations over time, causing deviations from the baseline or security standards.

73
MCQmedium

A security analyst is configuring a vulnerability scanner for a new deployment. The scanner must be able to authenticate to targets to perform deep configuration audits against CIS Benchmarks. Which type of scan should the analyst configure?

A.Credentialed scan
B.Unauthenticated scan
C.Passive scan
D.External scan
AnswerA

Credentialed scans utilize valid administrative or user credentials to log directly into target systems, enabling the scanner to inspect local registries, installed software versions, and configuration files. This deep visibility allows for the identification of missing patches and misconfigurations that are invisible from the network perspective, minimizing false positives and negatives.

Why this answer

A credentialed scan supplies valid credentials (e.g., SSH keys, SMB accounts, or API tokens) to the scanner, allowing it to log into targets and inspect local configuration, registry settings, file permissions, and patch levels. This deep access is required to audit against CIS Benchmarks, which specify OS and application configuration hardening checks that cannot be assessed externally.

Exam trap

CS0-004 often tests the confusion between credentialed vs. external scans — candidates pick 'external' thinking it implies deep access, when external describes vantage point and credentialed describes authentication depth required for CIS Benchmark audits.

How to eliminate wrong answers

Option B is wrong because an unauthenticated scan only probes externally visible services and banners, missing local configuration details needed for CIS Benchmark audits. Option C is wrong because a passive scan observes network traffic without actively querying targets, so it cannot authenticate or enumerate configuration settings. Option D is wrong because an external scan is defined by its vantage point (outside the network) rather than its authentication method — an external scan can be credentialed or not, and the question specifically requires authentication for deep configuration audits.

74
MCQmedium

During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch causes a regression in a key business application. Which of the following should the analyst do next?

A.Apply the patch to production but roll back if issues occur
B.Skip the patch and accept the risk
C.Deploy the patch to production and monitor for issues
D.Report the regression to the vendor and wait for a fixed patch
AnswerD

The standard operating procedure when finding a regression during patch testing is to document the defect and report it to the software vendor. This allows the vendor to refactor the code and release an updated, stable patch. While waiting, the organization should implement compensating controls to mitigate the underlying vulnerability without breaking production systems.

Why this answer

Reporting the regression to the vendor and waiting for a fixed patch is correct because the patch introduces a functional regression in a key business application, meaning it cannot be safely deployed. The proper patch management lifecycle requires that failed patches be documented, communicated to the vendor, and re-tested once a corrected version is available. This preserves both security and business continuity without accepting unmanaged risk.

Exam trap

CS0-004 often tests whether candidates confuse 'accepting risk' or 'deploying anyway' with proper remediation — the trap is choosing an action that bypasses the vendor feedback loop or violates change control.

How to eliminate wrong answers

Option A is wrong because applying a patch known to cause regressions to production violates change management principles and risks business disruption — 'roll back if issues occur' is reactive, not proactive. Option B is wrong because skipping the patch and accepting the risk leaves the known vulnerability unmitigated, which is unacceptable for a critical security patch without formal risk acceptance. Option C is wrong because deploying a patch already proven to break a key application to production is reckless and contradicts the purpose of staging tests.

75
MCQeasy

Which of the following tools is specifically designed for compliance scanning against security benchmarks such as CIS and STIG?

A.OpenVAS
B.Nessus
C.OpenSCAP
D.Trivy
AnswerC

Correct. OpenSCAP is built specifically around SCAP standards, consuming XCCDF checklists and OVAL definitions to evaluate a system's actual configuration against CIS Benchmarks or DISA STIGs and producing pass/fail compliance results, which is its primary design purpose.

Why this answer

OpenSCAP is an open-source tool specifically designed for compliance scanning against security benchmarks like CIS and STIG. It uses SCAP (Security Content Automation Protocol) standards to automate vulnerability management and compliance checking. It can evaluate systems against predefined policies and generate reports.

Exam trap

CS0-004 often tests the difference between vulnerability scanners and compliance scanners; candidates may pick Nessus or OpenVAS due to familiarity, but OpenSCAP is the specialized tool for CIS/STIG.

How to eliminate wrong answers

Option A is wrong because OpenVAS is a vulnerability scanner, not specifically for compliance benchmarks like CIS/STIG; it focuses on detecting vulnerabilities. Option B is wrong because Nessus is a commercial vulnerability scanner that can perform compliance checks but is not specifically designed for CIS/STIG; it requires plugins and is not open-source. Option D is wrong because Trivy is a vulnerability scanner for containers and other artifacts, not for compliance scanning against CIS/STIG benchmarks.

Page 1 of 2 · 124 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cysa Vulnerability Management questions.