Courseiva

CS0-004 · topic practice

Vulnerability Management practice questions

Domain 3 (Vulnerability Management) covers the vulnerability management lifecycle on CompTIA CySA+ CS0-004: asset discovery, scanning, analysis, prioritization, and remediation verification. Questions present analyst scenarios involving tools like Nessus, OpenVAS, Lynis, and Nmap, asking you to interpret findings, choose the right tool, identify misconfigurations, and validate that patches actually resolved the risk.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Vulnerability Management

What the exam tests

What to know about Vulnerability Management

You must be able to run and interpret vulnerability scans, prioritize findings using CVSS plus business context, and verify remediation. The single most important thing: confirm fixes with a follow-up scan or validation step rather than trusting that patching alone closed the risk.

Selecting scanning tools (Nessus, OpenVAS, Qualys, Nmap) for asset discovery, credentialed scans, and vulnerability detection

Interpreting CVSS base, temporal, and environmental scores plus CVE/CWE data to prioritize remediation

Recognizing misconfigurations in Kubernetes, cloud, and Linux systems, including world-writable files and weak permissions

Verifying remediation through rescanning, patch validation, and confirming fixes in staging before production deployment

Watch out for

Common Vulnerability Management exam traps

  • ▸Treating CVSS base score alone as the priority driver, ignoring asset criticality, exploitability, and environmental context.
  • ▸Confusing compliance scanning tools like Lynis with full vulnerability scanners such as Nessus or OpenVAS.
  • ▸Assuming a patch applied successfully equals a resolved vulnerability without rescanning or validating the fix.

Practice set

Vulnerability Management questions

20 questions · select your answer, then reveal the explanation

During a vulnerability assessment, a security analyst runs a scan using OpenVAS and reviews the results. One finding indicates a plugin with ID 12345 that detects a missing patch for CVE-2023-1234 on a Linux server. The server is a critical domain controller. Which step of the vulnerability lifecycle is the analyst currently performing?

An organization uses a DAST tool to scan a web application. The scanner reports a finding where user input is reflected in the HTTP response without proper encoding. Which OWASP Top 10 category best describes this vulnerability?

A security analyst is configuring a compliance scanner to check Linux servers against the CIS Benchmark. The analyst wants to ensure that only foundational security configurations are enforced to avoid breaking production applications. Which TWO CIS Benchmark levels would be most appropriate for this environment? (Select TWO)

A security analyst is reviewing the output of a vulnerability scanner that uses CVSS v3.1. The analyst wants to understand the impact metrics. Which THREE of the following are impact metrics in the CVSS v3.1 base score? (Select THREE.)

A security analyst is reviewing a DAST scan result for a web application. The scanner reports a finding that allows an attacker to redirect users to a malicious site via a parameter in the URL. Which OWASP Top 10 category does this finding most likely belong to?

A security analyst is using Burp Suite to test a web application for vulnerabilities. Which TWO of the following are common web application vulnerabilities that can be detected using Burp Suite? (Select TWO)

A security analyst is conducting a vulnerability assessment on a cloud environment and needs to select a tool to scan for misconfigurations against the CIS AWS Foundations Benchmark. Which TWO of the following tools are capable of performing compliance scanning against cloud benchmarks? (Select TWO.)

A security analyst is reviewing the results of a web application vulnerability scan and needs to identify the vulnerabilities that are part of the OWASP Top 10 (2021) category 'Injection'. Which THREE of the following vulnerabilities fall under this category? (Select THREE.)

A vulnerability scan identifies a plugin output for 'SMB Signing Disabled' on a Windows server. The CVSS v3.1 base score is 5.3 (Medium). The asset is a file server used only internally. The organization has decided not to enable SMB signing due to performance concerns. Which of the following is the BEST compensating control?

A security analyst is performing a cloud security assessment for an AWS environment. Which THREE of the following configurations would be considered CIS AWS Foundations Benchmark violations?

During a vulnerability assessment, a security analyst uses Nessus to scan a network. Which type of scan is most appropriate to identify live hosts and open ports without causing significant disruption?

A security analyst is performing an API vulnerability test. Which THREE of the following are common API vulnerabilities according to OWASP? (Select THREE.)

A cloud security team is using a container image scanning tool and finds a vulnerability in a base image used by many containers. The vulnerability is rated CVSS 7.5 and has a high EPSS score. However, rebuilding all containers with a patched base image will take significant time. What is the best immediate action?

A cybersecurity analyst is reviewing the configuration of a Linux server against CIS Benchmarks. The analyst notices that several settings deviate from the recommended baseline. Which TWO of the following are most likely to be considered Level 1 CIS Benchmark recommendations?

A security analyst is reviewing a compliance scan report for a DoD environment that uses Security Technical Implementation Guides (STIGs). The report indicates several failures. Which TWO of the following are likely STIG requirements for a Windows 10 system?

A security analyst is prioritizing vulnerabilities for remediation. The analyst has identified several vulnerabilities with CVSS scores, but wants to incorporate additional context to ensure the most critical vulnerabilities are addressed first. Which TWO factors should the analyst consider beyond the CVSS base score? (Choose two.)

A security team is conducting a vulnerability assessment on a web application that uses a SQL database backend. During a manual test, the tester enters a single quote in the username field and receives a database error message that includes the SQL query and database version. The tester wants to confirm whether this is a true SQL injection vulnerability and then exploit it to extract data. Which of the following actions should the tester take NEXT to confirm and exploit the vulnerability?

A security analyst is reviewing a vulnerability scan report from a credentialed scan of a Windows Server 2019 host. The report shows a critical vulnerability in a Microsoft library, but the analyst knows the host has the latest cumulative updates installed. The analyst runs an unauthenticated scan and the vulnerability does not appear. Which of the following best explains this discrepancy?

A security analyst is configuring a vulnerability scan of a web application. The analyst wants to identify vulnerabilities such as SQL injection and cross-site scripting. The scan must not modify any data in the application. Which of the following scan types should the analyst use?

A security analyst is reviewing a vulnerability scan report and needs to prioritize remediation. The analyst has access to CVSS v3.1 base scores, EPSS scores, and asset criticality ratings. Which of the following factors should the analyst consider to effectively prioritize the vulnerabilities? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Vulnerability Management sessions

Start a Vulnerability Management only practice session

Every question in these sessions is drawn from the Vulnerability Management domain — nothing else.

Related practice questions

Related CS0-004 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CS0-004 exam test about Vulnerability Management?
You must be able to run and interpret vulnerability scans, prioritize findings using CVSS plus business context, and verify remediation. The single most important thing: confirm fixes with a follow-up scan or validation step rather than trusting that patching alone closed the risk.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Vulnerability Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Vulnerability Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CS0-004 topics?
Use the topic links above to move to related areas, or go back to the CS0-004 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CS0-004 exam covers. They are not copied from any real exam or dump site.