Courseiva

CCNA Cysa Vulnerability Management Questions

49 of 124 questions · Page 2/2 · Cysa Vulnerability Management topic · Answers revealed

76
MCQeasy

Which of the following best describes the purpose of the CISA Known Exploited Vulnerabilities (KEV) catalog in vulnerability management?

A.It lists vulnerabilities that are known to have been exploited in the wild
B.It provides a framework for conducting penetration tests
C.It provides a scoring system for vulnerability severity
D.It offers a database of configuration baselines for operating systems
AnswerA

The CISA KEV catalog's defining criterion is real-world exploitation evidence; CISA adds a CVE only after confirming it has been actively exploited in the wild, which is why federal agencies under Binding Operational Directive 22-01 must remediate KEV-listed vulnerabilities on an accelerated timeline regardless of their CVSS score.

Why this answer

The CISA Known Exploited Vulnerabilities (KEV) catalog is a authoritative list maintained by CISA that enumerates vulnerabilities confirmed to have been exploited in the wild. Its purpose is to help organizations prioritize remediation by focusing on vulnerabilities with active exploitation evidence, not theoretical risk. This makes it a key input for risk-based vulnerability management and for meeting Binding Operational Directive 22-01 requirements for federal agencies.

Exam trap

CS0-004 often tests the distinction between vulnerability scoring (CVSS), exploitation evidence (KEV), and testing frameworks (PTES), so candidates must not confuse the KEV catalog with severity scoring or penetration testing methodologies.

How to eliminate wrong answers

Option B is wrong because penetration testing frameworks are methodologies like PTES, OWASP Testing Guide, or MITRE ATT&CK, not the KEV catalog. Option C is wrong because vulnerability severity scoring is provided by systems like CVSS (Common Vulnerability Scoring System), not KEV. Option D is wrong because configuration baselines are published by CIS Benchmarks, DISA STIGs, or NIST, not the KEV catalog.

77
MCQhard

A security analyst discovers a critical vulnerability in a web application that allows an attacker to trigger server-side requests from the application server. Which OWASP Top 10 category does this vulnerability belong to?

A.Broken Access Control
B.Security Misconfiguration
C.Injection
D.Server-Side Request Forgery (SSRF)
AnswerD

Server-Side Request Forgery (SSRF) occurs when a web application fetches a remote resource without validating the user-supplied URL. This allows an attacker to coerce the vulnerable server into sending crafted requests to internal-only resources, such as loopback interfaces, local databases, or cloud metadata endpoints (like AWS IMDSv1), effectively bypassing perimeter firewalls.

Why this answer

Server-Side Request Forgery (SSRF) is a distinct category in OWASP Top 10 (A10:2021).

78
MCQmedium

A security analyst is using Qualys to perform a vulnerability scan on a public-facing web server. The scan results show that the server is running an outdated version of Apache HTTP Server with multiple known vulnerabilities. The analyst checks the vendor security advisories and finds that a patch was released three months ago. However, the server is in a staging environment and not yet in production. What should the analyst recommend?

A.Only patch if the vulnerability is rated critical.
B.Patch the server immediately because it poses a risk to the staging network.
C.Do not patch because the server is not in production.
D.Wait until the server moves to production to patch.
AnswerB

Staging environments often mirror production configurations and may reside on networks with access to sensitive internal resources or active directory domains. Patching this vulnerability immediately is critical because an attacker could exploit the staging server to establish a foothold and perform lateral movement across the corporate network.

Why this answer

Even in staging, an unpatched public-facing web server with known Apache vulnerabilities is exploitable and can serve as a pivot point into the staging network or be used to attack other environments. Best practice is to patch immediately regardless of environment, because staging often shares credentials, network paths, or data with production. Deferring patching until production migration compounds risk.

Exam trap

CS0-004 often tests the misconception that non-production environments are low risk, when internet-facing staging hosts with known CVEs are prime targets for lateral movement.

How to eliminate wrong answers

Option A is wrong because severity ratings are contextual — a medium-severity flaw on an internet-facing host can still be chained into a critical exploit, and selective patching based only on CVSS ignores exposure. Option C is wrong because 'not in production' does not mean 'not exposed' — staging environments are frequently internet-accessible and hold sensitive test data. Option D is wrong because waiting until production migration means the vulnerable version is promoted into production, exactly when the risk is highest.

79
MCQmedium

A vulnerability scanner reports a finding with a CVSS v3.1 base score of 7.5 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. What does this indicate about the vulnerability?

A.It has high impact on integrity
B.It requires authentication to exploit
C.It has high impact on confidentiality
D.It has high impact on availability
AnswerD

The A component of the CVSS v3.1 vector is H, which is the Availability Impact metric and indicates that the exploit can cause a total loss of availability, such as a denial of service. Unlike the C and I metrics, which are both N, the A metric is the only one rated high, so this option correctly identifies the finding's high impact on availability.

Why this answer

The vector shows high impact to availability (A:H) and no impact to confidentiality or integrity, so the vulnerability primarily affects availability.

80
MCQmedium

A security analyst is using Burp Suite to test an API endpoint. The analyst notices that the API returns detailed error messages when invalid input is provided, revealing database schema information. Which OWASP Top 10 category does this issue primarily relate to?

A.Injection
B.Security Misconfiguration
C.Broken Access Control
D.Cryptographic Failures
AnswerB

Verbose error messages, such as stack traces or database debugging information returned by an API endpoint, represent a classic security misconfiguration. Properly configuring the application server to suppress detailed debugging outputs and return generic error messages prevents attackers from mapping the internal architecture and finding exploitable vectors.

Why this answer

Detailed error messages revealing internal details are a form of security misconfiguration. The OWASP Top 10 category 'Security Misconfiguration' includes verbose error messages that leak information.

81
Multi-Selecteasy

A security analyst is using a vulnerability scanner to identify missing patches on Windows servers. The scanner uses plugins that reference Common Vulnerabilities and Exposures (CVE) identifiers. Which THREE of the following are components of a CVSS v3.1 base score vector?

Select 3 answers
A.Attack Vector (AV)
B.Confidentiality (C)
C.Privileges Required (PR)
D.Remediation Level (RL)
E.Exploitability (E)
AnswersA, B, C

Attack Vector (AV) is a base metric that describes the context by which a vulnerability can be exploited, such as network, adjacent, local, or physical. This metric directly influences the CVSS exploitability subscore and is fundamental because it determines the remote vs. local nature of the attack. A network attack vector is typically the most severe because it allows exploitation from anywhere on the internet without prior access.

Why this answer

The CVSS v3.1 base score vector is composed of Exploitability metrics (Attack Vector, Attack Complexity, Privileges Required, User Interaction) and Impact metrics (Confidentiality, Integrity, Availability). Option A, Attack Vector (AV), is correct because AV is an Exploitability metric in the base group, with values Network (N), Adjacent (A), Local (L), and Physical (P). Option B, Confidentiality (C), is correct because C is one of the three Impact metrics (C/I/A) in the base score, reflecting the degree of confidentiality loss.

Option C, Privileges Required (PR), is correct because PR is an Exploitability metric in the base group, with values None (N), Low (L), and High (H). Option D, Remediation Level (RL), is incorrect because RL belongs to the Temporal score group, not the base score. Option E, Exploitability (E), is incorrect because E is a Temporal metric (with values Unproven, Proof-of-Concept, Functional, High, Not Defined), not a base metric.

Exam trap

CS0-004 often tests whether candidates can distinguish Base metrics from Temporal metrics, tricking them into selecting Exploitability (E) or Remediation Level (RL) because those sound like core vulnerability characteristics.

82
MCQhard

An organization uses OpenSCAP to perform compliance scanning against STIGs for DoD environments. A scan reveals that several systems are non-compliant with STIG ID: V-XXXXX requiring 'The system must disable the guest account.' The configuration drift detection tool shows that the guest account was re-enabled after a recent patch. What is the MOST effective course of action?

A.Update the system baseline to enforce the guest account disabled state via Group Policy.
B.Apply an exception to the STIG requirement for these systems.
C.Re-run the OpenSCAP scan after the next patch cycle.
D.Manually disable the guest account on each non-compliant system.
AnswerA

Updating the Active Directory Group Policy Objects (GPOs) to enforce the disabled state of the guest account ensures centralized, automated remediation across all target systems. This approach establishes a permanent configuration baseline that actively prevents configuration drift, aligning the environment with the required STIG profile validated by OpenSCAP.

Why this answer

Configuration drift indicates that patches or changes are reverting settings. The most effective action is to update the baseline configuration management tool (e.g., Group Policy) to enforce the setting automatically.

83
MCQmedium

An organization is implementing a patch management process and wants to track compliance. They deploy patches to a test group of systems before rolling out to the entire environment. After patching the test group, they run a vulnerability scan and find that 95% of the vulnerabilities are resolved. What should the organization do next?

A.Run another scan on the test group in a week to confirm persistence.
B.Immediately deploy the patch to all systems without further testing.
C.Skip full deployment and rely on the test group results.
D.Verify the patch on test systems and then proceed with full deployment through change management.
AnswerD

This option aligns with established security best practices by ensuring the patch is first validated for efficacy and stability on test systems before proceeding. Utilizing the organization's formal change management process ensures that the production rollout is coordinated, scheduled during maintenance windows, documented, and equipped with a rollback plan to minimize operational impact.

Why this answer

After successful testing, the next step is to deploy the patch to the rest of the environment, following change management procedures.

84
MCQhard

A security team discovers a critical vulnerability in a widely used software component. The vulnerability has a CVSS score of 9.0, but there is no known exploit or patch available yet. However, the software vendor has released a workaround. According to the vulnerability management lifecycle, which action should the team prioritize first?

A.Wait for the vendor to release a patch before taking any action
B.Remove the affected component from all systems immediately
C.Increase monitoring of the affected systems but take no other action
D.Apply the workaround as a compensating control
AnswerD

Applying a workaround as a compensating control is the most appropriate immediate action when a critical vulnerability is discovered and a vendor patch is not yet available. A compensating control is an alternative security measure that reduces the risk to an acceptable level until a permanent solution can be implemented. This approach effectively mitigates the immediate threat without causing undue operational disruption, balancing security with business continuity.

Why this answer

Since no patch is available, the team should apply compensating controls to mitigate the risk. Remediation typically involves patching, but if not possible, compensating controls are the next best step.

85
Multi-Selectmedium

An organization is implementing security hardening for Kubernetes clusters. Which THREE of the following are common Kubernetes misconfigurations that should be addressed? (Select THREE)

Select 3 answers
A.Using namespaces to isolate workloads
B.Implementing network policies
C.Using hostPath mounts without restrictions
D.Running containers in privileged mode
E.Overly permissive RBAC roles
AnswersC, D, E

HostPath mounts allow a pod to mount an arbitrary path from the underlying node's filesystem directly into the container. Without restrictions such as requiring read-only mounts, allowing only specific directories, or disabling hostPath when possible, a compromised container can read or modify sensitive host files, plant malicious executables, or even achieve full node compromise. This is a critical misconfiguration that directly exposes the host and is absolutely a security risk.

Why this answer

Option C is correct because hostPath mounts without restrictions let a pod access the node's filesystem, enabling container escape, node compromise, and tampering with kubelet or other host files, so they should be limited via Pod Security Admission or OPA/Gatekeeper policies. Option D is correct because privileged containers run with all Linux capabilities and unrestricted device access, effectively granting root on the host and bypassing container isolation, so privileged: true should be disallowed except for tightly controlled system workloads. Option E is correct because overly permissive RBAC roles, such as wildcard verbs/resources or cluster-admin bindings, violate least privilege and let compromised service accounts read secrets, create pods, or escalate across the cluster.

Options A and B are not misconfigurations: using namespaces to isolate workloads and implementing network policies are recommended hardening practices that segment resources and restrict pod-to-pod traffic.

Exam trap

CS0-004 often tests whether candidates can distinguish security best practices (namespaces, network policies) from actual misconfigurations (hostPath, privileged mode, permissive RBAC); selecting a best practice as a misconfiguration is the common error.

86
Multi-Selecthard

A security team is implementing container security scanning in their CI/CD pipeline. They want to scan container images for vulnerabilities and Kubernetes misconfigurations. Which THREE tools from the following list are best suited for this purpose? (Select THREE)

Select 3 answers
A.Burp Suite
B.Trivy
C.OpenSCAP
D.Clair
E.Snyk
AnswersB, D, E

Trivy is an open-source, fast, and comprehensive vulnerability scanner designed specifically for container images. It scans both OS packages (e.g., Alpine, Debian) and application dependencies (e.g., Python, Node.js) by comparing against a continuously updated CVE database, and it can be easily embedded into CI/CD pipelines with a simple CLI without requiring a separate server. Its low false-positive rate and support for multiple input formats (e.g., Docker, Podman, OCI) make it the most straightforward and effective choice among these options for the security team's container scanning need.

Why this answer

Trivy (B) is a purpose-built container and Kubernetes scanner that detects OS package and language dependency CVEs in images and also checks Kubernetes manifests and cluster configurations for misconfigurations, making it a direct fit for both requirements. Clair (D) is an open-source static analyzer from CoreOS/Quay that inspects container image layers against vulnerability databases, so it is well suited for image vulnerability scanning in a CI/CD pipeline. Snyk (E) provides container image vulnerability scanning plus Kubernetes and IaC misconfiguration detection, and it integrates natively into CI/CD workflows, satisfying both stated goals.

Burp Suite (A) is a web application security testing proxy for runtime HTTP traffic, not a container image or Kubernetes configuration scanner, so it does not belong. OpenSCAP (C) is a compliance and vulnerability scanner based on SCAP for hosts and operating systems, not for container image layers or Kubernetes misconfigurations, so it is not the best fit here.

Exam trap

The trap is selecting general-purpose security tools like Burp Suite or OpenSCAP because they are well-known, but the question specifically requires container image and Kubernetes misconfiguration scanning, which only Trivy, Clair, and Snyk address.

87
Multi-Selecthard

A security analyst is performing an API vulnerability test using OWASP ZAP. The analyst finds several issues. Which THREE of the following are common API vulnerabilities according to OWASP? (Select THREE.)

Select 3 answers
A.Broken Object Level Authorization
B.Excessive Data Exposure
C.SQL Injection
D.Cross-Site Scripting (XSS)
E.Broken Authentication
AnswersA, B, E

Broken Object Level Authorization (BOLA) is the most direct and correct answer because it occurs when an API fails to enforce per-object permissions, allowing an attacker to access, modify, or delete another user's data simply by substituting an object ID in an API request. For example, changing 'GET /api/user/123' to 'GET /api/user/456' can expose another user's private information if the server does not verify that the authenticated principal owns the requested object. This flaw is specifically catalogued as API1:2019 in the OWASP API Top 10 and is a primary focus of API penetration testing.

Why this answer

Broken Object Level Authorization (A) is correct because it is the #1 item on the OWASP API Security Top 10, occurring when an API fails to verify that the requesting user owns or is authorized to access the specific object referenced by an ID in the request (e.g., /api/users/123), allowing horizontal privilege escalation via IDOR-style attacks. Excessive Data Exposure (B) is correct because it is a recognized OWASP API risk where APIs return full objects with sensitive fields (PII, tokens, internal attributes) and rely on the client to filter, exposing data the consumer should never receive. Broken Authentication (E) is correct because it is a core OWASP API Security Top 10 category covering weak credential handling, missing token validation, improper JWT verification, and absent rate limiting on authentication endpoints.

SQL Injection (C) and Cross-Site Scripting (D) are not API-specific OWASP API Top 10 categories; they are classic web application vulnerabilities listed in the OWASP Top 10 for web apps, and while an API could theoretically be affected, they are not among the API-specific vulnerabilities the question asks for.

Exam trap

CS0-004 often tests whether candidates can distinguish the OWASP API Security Top 10 from the classic OWASP Top 10 web application list — SQL Injection and XSS are web-app categories, not API-specific ones, so candidates who select them lose the question.

88
MCQmedium

A vulnerability management team has identified a critical vulnerability with a CVSS score of 9.8. The vulnerability affects a public-facing web server that handles sensitive customer data. The team decides to apply a patch immediately without going through the normal patch testing cycle. What type of patching procedure is this?

A.Rolling patch deployment
B.Patch compliance tracking
C.Emergency patching
D.Standard patch management
AnswerC

Emergency patching is a specialized, expedited process designed to rapidly deploy critical security updates to production systems, often bypassing standard testing and change management protocols due to the severe and immediate risk posed by a newly discovered vulnerability. Its primary objective is to quickly mitigate an active threat or prevent imminent exploitation, prioritizing risk reduction over typical operational considerations like extensive pre-deployment testing or scheduled maintenance windows. This approach is reserved for vulnerabilities deemed critical enough to warrant immediate action.

Why this answer

When a critical vulnerability is actively exploited or poses immediate risk, emergency patching procedures are used to expedite deployment without standard testing.

89
MCQhard

A security team uses the Common Vulnerability Scoring System (CVSS) v3.1 to prioritize vulnerabilities. They find a vulnerability with a base score of 7.5 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. However, the asset is a public-facing web server with no backups. The team also checks the Exploit Prediction Scoring System (EPSS) and sees a score of 0.95 (95% probability of exploitation in the next 30 days). Which action should the team take first based on prioritizing by risk?

A.Expedite patch testing and deployment, and consider emergency change procedures
B.Apply the patch within the next 30 days as part of routine maintenance
C.Implement a network-based intrusion prevention system signature to block exploitation attempts
D.Deploy the patch immediately in the production environment without testing
AnswerA

When a critical asset is affected by a vulnerability with a high Exploit Prediction Scoring System (EPSS) score, the probability of active exploitation is imminent. Expediting patch testing through an accelerated QA process and utilizing emergency change management procedures balances the urgent need to remediate the flaw with the necessity of preventing operational disruption. This approach ensures the vulnerability is closed rapidly without bypassing critical stability checks.

Why this answer

With a CVSS base score of 7.5 (High) affecting a public-facing web server, no backups, and an EPSS score of 0.95 indicating a 95% probability of exploitation within 30 days, the risk is extreme — active exploitation is imminent and recovery would be impossible without backups. The correct first action is to expedite patch testing and deployment while invoking emergency change procedures to compress the normal change-management timeline without abandoning testing. This balances urgency with the operational discipline required to avoid introducing new outages.

Exam trap

CS0-004 often tests whether candidates over-index on a single metric — the trap is choosing 'patch within 30 days' based on the High (not Critical) CVSS score while ignoring the EPSS 0.95 and the no-backup context that together demand emergency action.

How to eliminate wrong answers

Option B is wrong because a 30-day routine maintenance window is far too slow given a 95% EPSS exploitation probability — the server would likely be compromised before the patch lands. Option C is wrong because an IPS signature is a compensating control that may not exist for a zero-day or may be bypassed by obfuscation; it does not remediate the underlying vulnerability and should not be the first action. Option D is wrong because deploying an untested patch to production violates change-management discipline and risks an outage on a critical public-facing server — 'expedite testing' is the key phrase distinguishing A from D.

90
MCQmedium

A vulnerability management analyst is reviewing scan results from a recent Nessus scan. The analyst notices a plugin with the output: 'The remote host is missing a security patch for CVE-2023-1234. The patch was released by the vendor on 2023-05-01.' Which phase of the vulnerability lifecycle is the analyst currently performing?

A.Prioritization
B.Remediation
C.Verification
D.Discovery
AnswerD

Discovery is the fundamental phase of the vulnerability management lifecycle focused on identifying active assets and detecting their associated vulnerabilities through automated scanning. When an analyst reviews raw scan results, they are actively engaging in this phase to establish a baseline of the organization's current attack surface and security posture.

Why this answer

The analyst is reviewing scan results to identify vulnerabilities, which is the discovery phase of the vulnerability lifecycle.

91
MCQmedium

A security analyst is reviewing a DAST report from Burp Suite for a web application. The report indicates a potential Server-Side Request Forgery (SSRF) vulnerability in a feature that fetches URLs. Which of the following is the most effective mitigation?

A.Use a whitelist of allowed URLs and validate user input against it.
B.Disable the URL fetching feature entirely.
C.Increase memory limits on the server to prevent resource exhaustion.
D.Implement a Web Application Firewall (WAF) to block malicious requests.
AnswerA

Implementing a strict whitelist of permitted domains or IP addresses is the most effective mitigation against Server-Side Request Forgery (SSRF). By validating all user-supplied input against this predefined list at the application layer, the server is restricted from initiating outbound connections to arbitrary external destinations or internal loopback addresses. This directly neutralizes the threat vector while maintaining necessary application functionality.

Why this answer

SSRF can be mitigated by validating and sanitizing user input, whitelisting allowed URLs, and blocking access to internal networks.

92
MCQmedium

During a vulnerability assessment, a security analyst discovers a critical vulnerability affecting a legacy application that cannot be patched due to vendor end-of-life status. Which of the following is the BEST next step?

A.Document the risk and implement compensating controls
B.Remove the legacy application from the network immediately
C.Disable the application until a patch becomes available
D.Apply a virtual patch via an intrusion prevention system
AnswerA

When a legacy application cannot be patched, the vulnerability management lifecycle dictates that the risk must be formally accepted and documented in the risk register. To mitigate the exposure while maintaining business operations, the organization must implement compensating controls, such as network segmentation or strict access control lists, to reduce the likelihood or impact of exploitation.

Why this answer

When a patch is not available, implementing compensating controls is the best approach to mitigate risk. This may include network segmentation, access controls, or additional monitoring.

93
MCQmedium

A security analyst is reviewing a vulnerability scan report and sees a finding for a web application with a CVSS v3.1 base score of 6.1. The vector string is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. Which OWASP Top 10 category does this vulnerability most likely belong to?

A.A03: Injection
B.A05: Security Misconfiguration
C.A06: Vulnerable and Outdated Components
D.A01: Broken Access Control
AnswerA

In the OWASP Top 10:2021 framework, Cross-Site Scripting (XSS) has been consolidated into the A03: Injection category. Reflected XSS occurs when untrusted user input is dynamically injected into a web application's response without proper sanitization or encoding. Consequently, a vulnerability scan identifying a reflected XSS vulnerability with a CVSS vector indicating user interaction and scope change directly maps to this category.

Why this answer

The vector indicates Reflected XSS (requires user interaction, scope change, low CIA impact). Reflected XSS is part of the OWASP Top 10 category 'Injection' (2017) or 'Cross-site Scripting' (2021). However, the most direct is Cross-site Scripting (XSS).

94
MCQmedium

A vulnerability management team is prioritizing remediation of several vulnerabilities. They have access to EPSS scores and the CISA KEV catalog. Which factor should they consider FIRST when deciding which vulnerability to remediate?

A.The vulnerability with the highest base CVSS score
B.The vulnerability listed in the CISA Known Exploited Vulnerabilities catalog
C.The vulnerability affecting the most critical asset
D.The vulnerability with the highest EPSS score
AnswerB

The Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities with documented, active exploitation in the wild. Remediation of these flaws must be prioritized because they represent immediate, validated threat vectors that adversaries are currently leveraging to compromise systems. Addressing KEV-listed vulnerabilities directly reduces the organization's active attack surface far more effectively than theoretical risk models.

Why this answer

The CISA KEV catalog contains vulnerabilities that are actively exploited in the wild. These pose immediate risk and should be addressed before others, regardless of EPSS score or other factors.

95
MCQmedium

An organization uses OpenSCAP to perform compliance scanning. The scan results indicate that a system fails to meet a STIG requirement. Which of the following best describes the purpose of STIGs?

A.They are used solely for web application security
B.They are vulnerability scoring standards
C.They are industry-standard benchmarks for cloud security
D.They are developed by the DoD to secure its information systems
AnswerD

STIGs are DoD-published configuration baselines that harden systems against known threats, so this option correctly identifies their origin and purpose. OpenSCAP evaluates a host against these mandated settings, and a failure means the system deviates from the DoD's required secure configuration.

Why this answer

STIGs (Security Technical Implementation Guides) are configuration standards developed by the Defense Information Systems Agency (DISA), a DoD agency, to provide mandatory technical security controls for hardening DoD information systems. They define specific settings, patch levels, and configuration baselines that systems must meet to be authorized for use within the DoD. OpenSCAP uses SCAP content (often derived from STIG benchmarks) to automatically assess compliance against these requirements, which is why a failed STIG check indicates a deviation from DoD-mandated configuration.

Exam trap

CS0-004 often tests the confusion between STIGs (DoD configuration hardening guides) and other security frameworks like CVSS (scoring), CIS Benchmarks (industry consensus), or NIST publications, so candidates must remember that STIGs are specifically DoD-developed and prescriptive, not scoring or general industry standards.

How to eliminate wrong answers

Option A is wrong because STIGs cover a broad range of systems—operating systems, databases, network devices, and applications—not solely web application security; web app security is only one small subset. Option B is wrong because vulnerability scoring is handled by standards like CVSS (Common Vulnerability Scoring System), which assigns numerical severity scores to vulnerabilities, whereas STIGs are prescriptive configuration checklists, not scoring systems. Option C is wrong because STIGs are government-developed and DoD-specific, not industry-standard cloud security benchmarks; cloud security benchmarks are typically produced by organizations like the Center for Internet Security (CIS) or the Cloud Security Alliance (CSA).

96
MCQeasy

A security analyst is reviewing a vulnerability scan report and sees a plugin with a CVSS v3.1 base score of 7.5. The attack vector is 'Network', attack complexity is 'Low', privileges required is 'None', user interaction is 'None', scope is 'Unchanged', and the confidentiality impact is 'High', but integrity and availability impacts are 'None'. This vulnerability is best described as:

A.A remote code execution vulnerability
B.A denial of service vulnerability
C.An information disclosure vulnerability
D.A privilege escalation vulnerability
AnswerC

An information disclosure vulnerability specifically exposes sensitive data to unauthorized parties without allowing them to alter system state or disrupt operations. Consequently, the CVSS metric for this vulnerability reflects a High Confidentiality impact, while the Integrity and Availability metrics remain at None or Low.

Why this answer

The vector indicates a remote, easily exploitable vulnerability that only affects confidentiality (e.g., information disclosure).

97
Multi-Selectmedium

A security analyst is performing a web application security assessment and identifies a potential cross-site scripting (XSS) vulnerability. The application is critical to business operations. Which TWO of the following are appropriate immediate actions?

Select 2 answers
A.Take the application offline immediately
B.Implement a web application firewall (WAF) rule to block XSS payloads
C.Ignore the finding because XSS is low risk
D.Notify law enforcement immediately
E.Report the vulnerability to the development team for remediation
AnswersB, E

Implementing a web application firewall (WAF) rule (e.g., using the OWASP Core Rule Set) immediately blocks known XSS payloads at the edge, providing a temporary mitigation that reduces exploitability without taking the application offline. The WAF can be tuned to inspect query strings, POST bodies, and headers for attack signatures, allowing the security team to protect users while the development team prepares a permanent patch. This is a standard first-line response for web vulnerabilities, but the WAF rule should be considered a compensating control, not a substitute for secure coding.

Why this answer

Option B is correct because deploying a WAF rule to block XSS payloads provides an immediate compensating control that mitigates exploitation attempts while a permanent code fix is developed, which is essential for a business-critical application that cannot simply be shut down. Option E is correct because reporting the vulnerability to the development team initiates proper remediation, such as output encoding, input validation, and context-aware escaping, addressing the root cause of the XSS flaw. Option A is not appropriate because taking a critical business application offline immediately would cause severe operational disruption; a compensating control is preferred first.

Option C is wrong because XSS is a serious vulnerability that can lead to session hijacking, credential theft, and data exfiltration, not a low-risk finding. Option D is incorrect because notifying law enforcement is not an immediate technical response to an internally discovered vulnerability; it would only apply in cases of confirmed criminal attack or breach with legal reporting requirements.

Exam trap

CS0-004 often tests the balance between security and availability; candidates may choose to take the application offline, but that is rarely the correct immediate action for a vulnerability unless actively exploited. The trap is overreacting versus underreacting.

98
MCQeasy

Which of the following vulnerability scanning tools is open source and commonly used for network vulnerability assessment?

A.Nessus
B.Qualys
C.Rapid7 InsightVM
D.OpenVAS
AnswerD

OpenVAS (Open Vulnerability Assessment System) is a fully open-source vulnerability scanner maintained by Greenbone Networks. It provides a comprehensive, community-driven feed of Network Vulnerability Tests (NVTs) under the GNU General Public License (GPL), allowing organizations to inspect, modify, and deploy the scanner without licensing fees.

Why this answer

OpenVAS is a well-known open-source vulnerability scanner.

99
MCQeasy

A security analyst is using OpenVAS to perform a vulnerability scan of an internal network. The scan completes and generates a report listing several vulnerabilities. What is the next step in the vulnerability lifecycle?

A.Prioritization
B.Verification
C.Reporting
D.Remediation
AnswerA

Immediately after scan results are generated, analysts must rank findings by exploitability, asset criticality, and business context so limited remediation resources are directed at the highest-impact vulnerabilities first, which is prioritization.

Why this answer

After discovery (scanning), the next step is prioritization of vulnerabilities based on risk, exploitability, and business impact.

100
MCQeasy

Which metric in the CVSS v3.1 base score indicates the level of access an attacker needs to exploit a vulnerability?

A.Privileges Required (PR)
B.Attack Vector (AV)
C.Attack Complexity (AC)
D.User Interaction (UI)
AnswerA

The Privileges Required (PR) metric measures the level of access privileges an attacker must possess prior to successfully exploiting the vulnerability. It is scored as None, Low, or High, directly reflecting whether the exploit requires administrative control, standard user access, or no authentication at all.

Why this answer

Privileges Required (PR) indicates the level of privileges an attacker must have before successfully exploiting the vulnerability.

101
MCQhard

A security team is implementing a patch management process for a large enterprise. They must ensure that patches are tested before deployment to production. The team has a staging environment that mirrors production. During patch testing, they discover that a critical security patch for a database server causes a performance degradation of 30% in a key application. What should the team do next?

A.Skip the patch and rely on existing security controls.
B.Apply the patch to production immediately because it fixes a critical vulnerability.
C.Contact the vendor for a fix or workaround, and implement compensating controls in the meantime.
D.Deploy the patch to a subset of production servers to test performance.
AnswerC

Engaging the vendor for a hotfix or documented workaround while layering compensating controls, such as WAF rules, enhanced monitoring, or restricted access, addresses the vulnerability's risk in the interim without forcing the team to accept either the security exposure or the measured performance degradation.

Why this answer

The patch is critical but causes performance issues. The best approach is to work with the vendor for a resolution or apply compensating controls until a fix is available. Applying the patch blindly may disrupt operations, while skipping it leaves the vulnerability unaddressed.

102
MCQhard

A security analyst is investigating a containerized environment. A scan using Trivy has identified a critical vulnerability in a container image. The container is running in a Kubernetes cluster with a Pod Security Policy that disallows privileged containers. Which additional concern should the analyst address?

A.The vulnerability is not exploitable due to the Pod Security Policy
B.The vulnerability is automatically mitigated because the container is not privileged
C.The analyst should ignore the vulnerability because the container is not privileged
D.The analyst should immediately patch the image, but also verify that the Pod Security Policy prevents privilege escalation
AnswerD

Because the Pod Security Policy reduces but does not eliminate the vulnerability's potential impact, the correct approach layers remediation with verification: patch the base image to remove the underlying flaw while also confirming the policy's privilege-escalation controls are properly enforced, ensuring both the root cause and the compensating control are addressed rather than relying on either alone.

Why this answer

A critical vulnerability in a container image remains a real risk even if the container is not privileged, because the vulnerability could still be exploited for data exfiltration, denial of service, or lateral movement within the cluster. The analyst should patch the image and also verify that the Pod Security Policy actually prevents privilege escalation, since misconfigurations or policy gaps could allow an attacker to escalate privileges after exploiting the vulnerability.

Exam trap

CS0-004 often tests the misconception that a Pod Security Policy or non-privileged container automatically neutralizes all vulnerabilities, when in fact it only blocks one specific escalation vector.

How to eliminate wrong answers

Option A is wrong because a Pod Security Policy disallowing privileged containers does not make a vulnerability non-exploitable; it only limits one escalation path. Option B is wrong because automatic mitigation is not guaranteed — the vulnerability may still be exploited through other vectors such as application-level flaws or container escape techniques that do not require privileged mode. Option C is wrong because ignoring a critical vulnerability is never acceptable; the policy reduces risk but does not eliminate it.

103
Multi-Selecthard

A vulnerability management analyst is prioritizing vulnerabilities for remediation. The analyst has the following information for three vulnerabilities: CVE-2023-1: CVSS 9.8, EPSS 0.9, asset criticality high; CVE-2023-2: CVSS 7.5, EPSS 0.01, asset criticality low; CVE-2023-3: CVSS 5.0, EPSS 0.8, asset criticality medium. According to best practices, which THREE factors should the analyst consider when prioritizing? (Select THREE)

Select 3 answers
A.CVSS score
B.CVE publication date
C.Asset criticality
D.EPSS score
E.Number of vendors affected
AnswersA, C, D

CVSS is a standardized severity score that synthesizes exploitability characteristics (attack vector, attack complexity, privileges required, user interaction) and impact metrics (confidentiality, integrity, availability) into a 0–10 score. In v3.x, this score provides the critical first filter for triage, allowing an analyst to quickly separate low-severity flaws from those that demand immediate attention. However, it is only a measure of intrinsic severity, not a guarantee of real-world exploitation, so it must be combined with threat likelihood and business impact. As a severity benchmark, it remains the primary initial factor in any prioritization workflow.

Why this answer

Option A (CVSS score) is correct because CVSS provides the standardized severity rating of a vulnerability's technical impact, and in this scenario the analyst is explicitly comparing scores such as 9.8, 7.5, and 5.0 to gauge relative severity. Option C (Asset criticality) is correct because the business value and exposure of the affected asset determine the real-world risk; a high-criticality asset raises the urgency of remediation regardless of raw severity. Option D (EPSS score) is correct because EPSS estimates the probability that a vulnerability will be exploited in the wild within the next 30 days, so values like 0.9 versus 0.01 strongly influence prioritization beyond CVSS alone.

Option B (CVE publication date) is not a standard prioritization factor, since age alone does not indicate exploitability or business impact. Option E (Number of vendors affected) is not a recognized risk-scoring input for prioritizing a specific vulnerability in a given environment.

Exam trap

CS0-004 often tests whether candidates default to CVSS alone — the trap is ignoring EPSS and asset criticality, which are essential for risk-based prioritization.

104
MCQmedium

A security analyst is reviewing a vulnerability scan report from Rapid7 InsightVM. The report shows that a Tomcat server has a plugin finding indicating that the 'Server' header is set to 'Apache-Coyote/1.1', which reveals the server version. Which type of vulnerability does this represent?

A.Broken access control
B.Injection vulnerability
C.Security misconfiguration
D.Cryptographic failure
AnswerC

Exposing detailed server version banners is a classic security misconfiguration that leaks valuable reconnaissance data to potential attackers. By failing to disable verbose headers or default error pages, administrators inadvertently assist adversaries in mapping out specific, exploitable vulnerabilities associated with that software version.

Why this answer

The 'Server' header revealing the server version is a security misconfiguration because it exposes unnecessary information that could aid attackers in targeting known vulnerabilities. This falls under the OWASP Top 10 category of Security Misconfiguration. It is not a direct vulnerability but a configuration weakness that should be remediated by suppressing version details.

Exam trap

CS0-004 often tests the classification of information disclosure as a security misconfiguration, where candidates might incorrectly label it as broken access control or injection.

How to eliminate wrong answers

Option A is wrong because broken access control involves unauthorized access to resources, not information disclosure via headers. Option B is wrong because injection vulnerabilities involve untrusted data being executed as code, not header information leakage. Option D is wrong because cryptographic failures involve weak encryption or key management, not server banner disclosure.

105
MCQeasy

A security analyst needs to verify that a critical patch was successfully applied to all endpoints in the organization after an emergency patch deployment. Which phase of the vulnerability lifecycle is the analyst performing?

A.Remediation
B.Prioritization
C.Discovery
D.Verification
AnswerD

Verification is the final, critical step in the vulnerability management lifecycle where analysts perform follow-up scans or manual checks to ensure the patch was correctly installed and the vulnerability is fully mitigated. This step prevents false positives and confirms that the remediation efforts were effective in reducing the organization's attack surface.

Why this answer

Verification ensures that remediation (patch application) was effective. It occurs after the fix is applied.

106
MCQeasy

A security analyst is reviewing a vulnerability scan report and sees a critical finding with a CVSS v3.1 base score of 9.8. The vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector component (AV:N)?

A.The attacker can exploit the vulnerability over a network from a remote system
B.The attacker must be on the same physical network segment
C.The attacker requires local access to the target system
D.The attacker must be physically present at the device
AnswerA

In the Common Vulnerability Scoring System (CVSS), an Attack Vector of Network (AV:N) means the vulnerability is exploitable from any remote system that can reach the target over a network connection. This includes sending specially crafted IP packets, protocol-specific requests, or application-layer payloads without requiring any prior authentication or local access. The attacker does not need to be co-located on the target's local subnet, merely capable of network connectivity.

Why this answer

In CVSS v3.1, the Attack Vector (AV) metric describes how the vulnerability is exploited. AV:N (Network) means the vulnerable component is reachable over a network layer (e.g., the internet or a LAN) and the attacker does not need local or physical access. This is the most severe AV value and contributes to the high base score of 9.8 in the given vector.

Exam trap

CS0-004 often tests the confusion between AV:N and AV:A, so candidates who read 'network' as 'same LAN segment' pick the adjacent value instead of the true network value.

How to eliminate wrong answers

Option B is wrong because 'same physical network segment' describes AV:A (Adjacent), which requires the attacker to be on the same shared network (e.g., same subnet or Bluetooth range), not AV:N. Option C is wrong because local access is AV:L (Local), where the attacker must execute code on the target or have a local shell. Option D is wrong because physical presence is AV:P (Physical), the least severe AV value, requiring hands-on access to the device.

107
Multi-Selectmedium

A security analyst is investigating a reported vulnerability in a web application. The team uses Burp Suite for DAST scanning. Which TWO of the following findings would be classified as injection vulnerabilities according to OWASP Top 10?

Select 2 answers
A.Use of a component with known vulnerabilities
B.Broken access control allowing privilege escalation
C.Stored XSS in the comment section
D.Security misconfiguration exposing directory listing
E.SQL injection in the login form
AnswersC, E

Stored XSS in the comment section is an injection vulnerability because the attacker injects executable client-side script (e.g., JavaScript) that is persisted on the server and later rendered in other users' browsers. Unlike SQL injection, which targets the database layer with structured query language, XSS targets the interpretation context of HTML/JavaScript in the victim's browser. The comment field fails to sanitize or encode user input, enabling script execution that can steal session cookies, deface pages, or perform actions on behalf of the target user.

Why this answer

Option C (Stored XSS in the comment section) is correct because cross-site scripting is classified under OWASP Top 10 A03:2021 Injection, where untrusted user input is interpreted as code (HTML/JavaScript) by the browser, and the stored variant persists the payload in the application's database. Option E (SQL injection in the login form) is correct because SQLi is the canonical injection flaw, where attacker-supplied input alters the structure of a SQL query executed by the backend database, also falling under A03:2021 Injection. Option A does not belong because using a component with known vulnerabilities maps to A06:2021 Vulnerable and Outdated Components, not injection.

Option B does not belong because broken access control is its own category, A01:2021, involving authorization failures rather than input being interpreted as code or commands. Option D does not belong because security misconfiguration maps to A05:2021 and concerns improper hardening (such as exposed directory listings), not injection.

Exam trap

The trap here is confusing other OWASP Top 10 categories (like broken access control or vulnerable components) with injection, because candidates may not recall that XSS is classified under injection in the 2021 list.

108
MCQhard

A security analyst is reviewing the results of a container image scan using Trivy. The scan reports a critical vulnerability in a base image layer. The development team states that the vulnerability is not exploitable because the affected library is not used in the application. According to vulnerability management best practices, what should the analyst do?

A.Accept the risk and close the finding.
B.Request that the development team remove the unused library and rebuild the image.
C.Ignore the finding since it is not exploitable.
D.Apply a compensating control at the network level to block exploitation.
AnswerB

The most effective remediation strategy for container security is to minimize the attack surface by practicing container hygiene. Requesting that the development team remove the unnecessary library and rebuild the base image permanently eliminates the vulnerability at the source, preventing it from being deployed into production environments.

Why this answer

Even if the library is not used, it is best practice to rebuild the image with a patched base image to eliminate the vulnerability and ensure compliance.

109
MCQhard

During a vulnerability assessment of a Kubernetes cluster, a security analyst finds that a container is running with privileged mode enabled and has a hostPath mount that grants write access to the host's /var/log directory. Which of the following is the most significant security risk associated with this configuration?

A.Data leakage through unrestricted storage access
B.Excessive network permissions allowing lateral movement
C.Potential for container escape and host node compromise
D.Increased attack surface due to unnecessary services running in the container
AnswerC

Running a container in privileged mode eliminates the isolation boundaries enforced by namespaces and cgroups, granting the container near-root access to the host. When combined with a hostPath mount, an attacker can easily access the host's filesystem, manipulate system binaries, interact with the host's container runtime socket, and achieve full container escape to compromise the underlying node.

Why this answer

A container running in privileged mode with a hostPath mount that grants write access to the host's /var/log directory poses a significant risk of container escape and host node compromise. Privileged mode gives the container almost all capabilities of the host, and the hostPath mount allows direct write access to host files, enabling an attacker to modify system logs, plant malware, or escalate privileges to the host.

Exam trap

CS0-004 often tests container security risks. Candidates might focus on data leakage or network permissions, but the combination of privileged mode and hostPath write access is a classic container escape vector leading to host compromise.

How to eliminate wrong answers

Option A is wrong because while data leakage is a concern, the write access to /var/log is more about integrity and potential code execution than just leakage. Option B is wrong because excessive network permissions are not indicated by privileged mode and hostPath mount; the risk is host compromise, not lateral movement. Option D is wrong because increased attack surface due to unnecessary services is a general risk, but the specific configuration of privileged mode and hostPath write access is far more severe, directly enabling host takeover.

110
MCQmedium

A security analyst is reviewing a vulnerability scan report and finds a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and impact of this vulnerability?

A.Adjacent attack vector, high impact on availability only
B.Network attack vector, high impact on confidentiality, integrity, and availability
C.Physical attack vector, medium impact on confidentiality
D.Local attack vector, low impact on confidentiality
AnswerB

This option accurately reflects a CVSS v3 vector string where the Attack Vector is Network, meaning the vulnerability can be exploited remotely over the internet. It also correctly identifies that the exploit results in a High impact rating for confidentiality, integrity, and availability, indicating total compromise of the affected system.

Why this answer

AV:N indicates network-based attack vector, meaning the vulnerability can be exploited remotely over the network. The CIA impact ratings are all High, indicating complete compromise of confidentiality, integrity, and availability.

111
Multi-Selecthard

A security analyst is conducting a dynamic application security testing (DAST) scan of a REST API. The scanner reports a potential Server-Side Request Forgery (SSRF) vulnerability. The analyst needs to confirm the finding manually. Which TWO of the following techniques are most appropriate for validating SSRF?

Select 2 answers
A.Submit a payload that triggers the server to send a request to an attacker-controlled external server (e.g., Burp Collaborator)
B.Craft a request that causes the server to make a request to an internal IP address (e.g., 127.0.0.1) and observe the response
C.Inject malicious SQL queries into input fields to see if they are executed
D.Attempt to upload a malicious file to the server
E.Modify HTTP headers to test for cross-site scripting
AnswersA, B

An out-of-band (OAST) SSRF test uses an external callback server like Burp Collaborator to detect when the application fetches an attacker-specified URL. If a DNS lookup or HTTP hit is received, it proves the server-side component is making the request as the victim, even when the response body is not reflected to the tester. This technique is essential for blind SSRF, where the application processes the response internally without echoing it back. It also confirms the vulnerability independently of any firewall or filtering on the inbound path.

Why this answer

Option A is correct because SSRF validation classically uses an out-of-band channel: submitting a payload that makes the vulnerable server issue a request to an attacker-controlled host such as Burp Collaborator, and then confirming the inbound DNS/HTTP interaction proves the server-side request was actually made. Option B is correct because SSRF is fundamentally about the server reaching resources the attacker cannot, so crafting input that causes the server to request an internal address like 127.0.0.1 (or 169.254.169.254 for cloud metadata) and observing a response or timing/error difference confirms the server is fetching attacker-influenced URLs. Option C is not appropriate because injecting SQL queries tests for SQL injection, a different vulnerability class, not server-side request forgery.

Option D is not appropriate because uploading a malicious file tests unrestricted file upload, not SSRF. Option E is not appropriate because modifying HTTP headers to test for cross-site scripting targets XSS, which is a client-side injection issue unrelated to SSRF.

Exam trap

CompTIA CS0-004 often tests whether candidates can distinguish SSRF validation (out-of-band callbacks, internal IP probing) from unrelated vulnerability tests like SQLi, file upload, or XSS that appear in the same option list.

112
MCQeasy

An organization uses OpenSCAP for compliance scanning. What is the primary purpose of OpenSCAP?

A.Vulnerability scanning
B.Intrusion detection
C.Penetration testing
D.Compliance scanning and configuration assessment
AnswerD

OpenSCAP evaluates systems against security baselines such as SCAP content and STIG profiles, checking configuration settings and reporting compliance deviations. This directly satisfies the scenario's compliance scanning purpose by automating configuration assessment against defined standards.

Why this answer

OpenSCAP is a tool for automated compliance checking against security policies like SCAP content.

113
MCQmedium

A security analyst is using a container image scanner to identify vulnerabilities in a Kubernetes deployment. Which of the following tools is specifically designed for container image scanning?

A.Trivy
B.OpenVAS
C.Nessus
D.Burp Suite
AnswerA

Trivy is an open-source vulnerability scanner specifically designed for containers, Kubernetes, and IaC templates. It excels at detecting vulnerabilities in OS packages and application dependencies within container images, making it ideal for integration into CI/CD pipelines.

Why this answer

Trivy is a popular open-source tool for scanning container images for vulnerabilities.

114
MCQmedium

A security analyst reviews a Nessus scan result for a web server. The plugin output indicates a critical vulnerability with CVSS v3.1 base score 9.8. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack complexity?

A.Low
B.Critical
C.Medium
D.High
AnswerA

The CVSS vector string 'AC:L' explicitly denotes a Low Attack Complexity. This means that a successful attack does not require specialized conditions beyond the attacker's control, nor does it demand extensive preparation or specific timing. Attackers can typically exploit such vulnerabilities with readily available techniques and resources, making the attack relatively straightforward and increasing its likelihood.

Why this answer

In the CVSS vector, AC:L means Attack Complexity is Low, indicating no special conditions are required for exploitation.

115
MCQmedium

A security analyst is configuring a vulnerability scanner to perform a scan of a network segment. The analyst wants to minimize the risk of disrupting critical production systems during the scan. Which of the following scanner settings should the analyst adjust?

A.Scan schedule
B.Scan intensity
C.Credentialed scanning
D.Plugin updates
AnswerB

Scan intensity controls the aggressiveness of the scan, including the number of concurrent connections and payloads sent. Lowering intensity reduces the risk of overwhelming production systems, which could cause outages. The analyst should set a lower intensity to avoid disruption while still identifying vulnerabilities. This setting directly addresses the need to balance thoroughness with system stability.

Why this answer

Scan intensity determines how aggressively the scanner probes systems, including the rate of connections and the types of checks performed. Lowering intensity reduces the chance of causing performance issues or crashes on production systems. While scheduling and credentialed scanning have their place, adjusting intensity is the most direct way to minimize disruption.

Plugin updates are unrelated to scan impact.

Exam trap

The trap here is assuming that scheduling the scan during off-peak hours is sufficient to prevent disruption, when the scan's intensity is the primary factor affecting system load.

116
MCQhard

During a configuration compliance scan using OpenSCAP, a security analyst finds that several Windows servers have the 'Network access: Do not allow anonymous enumeration of SAM accounts' setting set to 'Disabled'. This finding corresponds to a CIS Benchmark recommendation. Which of the following describes the most appropriate remediation step for this finding?

A.Disable the Guest account on all servers.
B.Apply a registry key to disable anonymous enumeration.
C.Restrict anonymous access using IPsec rules.
D.Enable the policy 'Network access: Do not allow anonymous enumeration of SAM accounts' via Group Policy.
AnswerD

This Group Policy setting directly addresses the OpenSCAP finding by preventing unauthenticated users from enumerating domain or local account names and shares. Enabling this policy enforces the recommended CIS benchmark control, securing the SAM database against reconnaissance techniques like null session enumeration without disrupting legitimate system operations.

Why this answer

The setting should be enabled to prevent anonymous enumeration of SAM accounts. The remediation is to change the policy setting via Group Policy or local security policy.

117
MCQmedium

A security analyst is reviewing a vulnerability scan report and notices that a plugin output indicates a potential misconfiguration in a web server that allows directory listing. The analyst wants to verify this finding manually. Which of the following tools would be most appropriate to confirm the vulnerability?

A.Burp Suite
B.Metasploit
C.Wireshark
D.Nmap
AnswerA

Burp Suite is an intercepting proxy designed specifically for web application security testing. It allows an analyst to intercept, modify, and replay HTTP/HTTPS requests to manually inspect the web server's responses. This makes it the ideal tool to safely and directly verify if directory listing is enabled on a specific web directory.

Why this answer

Burp Suite is a web application security testing tool that can be used to manually verify web vulnerabilities like directory listing by intercepting and modifying requests.

118
MCQeasy

A security analyst is using a DAST tool to test a web application. Which of the following vulnerabilities would the tool most likely identify?

A.Hardcoded credentials in source code
B.SQL injection
C.Outdated library versions
D.Insecure cryptographic algorithms in configuration
AnswerB

DAST tools excel at identifying input validation flaws like SQL injection by actively sending malicious payloads to application entry points and analyzing the HTTP responses. If the application returns database error messages or exhibits unexpected behavior, the tool flags the vulnerability in real-time.

Why this answer

DAST tools interact with the running application and can detect vulnerabilities like SQL injection by sending malicious inputs and observing responses.

119
MCQmedium

A security analyst is reviewing a DAST scan report for a web application. The report indicates a vulnerability where the application fails to properly validate user-supplied data before using it in a database query. This is most likely which type of vulnerability?

A.Cross-site scripting (XSS)
B.Security misconfiguration
C.Injection
D.Broken access control
AnswerC

Injection vulnerabilities occur when an application passes unfiltered, user-supplied input directly to an interpreter, such as a SQL database or system shell. This allows an attacker to manipulate the structure of the intended command, leading to unauthorized data access, modification, or arbitrary remote code execution on the host system.

Why this answer

Failure to validate user input before using in a database query is classic SQL injection (injection flaw).

120
MCQmedium

During a patch management process, an organization uses a staging environment to test patches before deployment. Which of the following is the primary purpose of patch testing in a staging environment?

A.To create a backup of production systems
B.To speed up the patch deployment process
C.To validate that the patch addresses the vulnerability without causing regressions
D.To comply with licensing requirements
AnswerC

The primary objective of staging is to verify that the patch successfully remediates the targeted security vulnerability while ensuring it does not break existing functionality or cause system regressions. This validation phase allows administrators to observe system behavior, application dependencies, and performance metrics under realistic conditions before a full production rollout.

Why this answer

The primary purpose of patch testing in a staging environment is to validate that the patch actually remediates the vulnerability it targets while ensuring it does not introduce regressions or break existing functionality. Staging mirrors production closely enough to catch compatibility issues before the patch reaches live systems, which is the core of a controlled patch management process.

Exam trap

CS0-004 often tests whether candidates confuse the purpose of patch testing (validate fix + no regressions) with adjacent activities like backups, speed, or licensing, which are plausible but incorrect.

How to eliminate wrong answers

Option A is wrong because creating backups of production systems is a separate backup/disaster-recovery activity, not the purpose of patch testing in staging. Option B is wrong because staging actually slows down deployment by adding a validation step — the goal is safety and correctness, not speed. Option D is wrong because licensing compliance is unrelated to patch testing; licensing is handled through asset management and procurement, not staging validation.

121
Multi-Selectmedium

A security analyst is prioritizing vulnerabilities for remediation. Which THREE factors from the CISA Known Exploited Vulnerabilities (KEV) catalog should the analyst consider? (Select THREE.)

Select 3 answers
A.EPSS probability score
B.Date the vulnerability was added to the catalog
C.CVSS base score
D.Vulnerability name or CVE ID
E.Affected vendor or product
AnswersB, D, E

The KEV catalog includes a 'Date Added' field that records when a vulnerability was first identified as known exploited, allowing security teams to prioritize based on how recent and relevant the active exploitation is. This date is crucial because newer entries often warrant immediate attention, as attackers may be actively leveraging them. In contrast to CVSS or EPSS scores, this date is a distinct component of the KEV record itself, making it the right field when consulting the catalog for prioritization.

Why this answer

The CISA KEV catalog entry for each vulnerability includes the date it was added to the catalog (option B), which indicates how long the vulnerability has been known to be actively exploited and helps prioritize remediation urgency. It also lists the vulnerability name or CVE ID (option D), which uniquely identifies the specific flaw so the analyst can map it to affected systems and track remediation. The affected vendor or product (option E) is likewise a core KEV field, telling the analyst which technologies are at risk and whether they are present in the environment.

EPSS probability score (option A) is not part of the KEV catalog; it comes from the separate EPSS model maintained by FIRST. CVSS base score (option C) is also not a KEV catalog field; it is published by NVD or the vendor and is not included in KEV entries.

Exam trap

The trap is confusing KEV catalog fields with external metrics like EPSS and CVSS — candidates pick those because they are familiar, but they are not part of the KEV catalog itself.

122
MCQhard

An analyst is reviewing a vulnerability scan report for a containerized application. The scan identifies a critical vulnerability in a base image used by multiple containers. The application is deployed in a Kubernetes cluster with network policies restricting ingress. The vulnerability has a CVSS v3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). However, the EPSS score is 0.001 (0.1%). Which of the following should the analyst prioritize?

A.Apply a virtual patch via a web application firewall (WAF)
B.Ignore the vulnerability because it is in a container image
C.Schedule the patch for the next maintenance window because of low EPSS and network controls
D.Immediately patch the vulnerability within 24 hours due to the high CVSS score
AnswerC

An EPSS score of 0.1% indicates the vulnerability has near-negligible real-world exploitation likelihood in the next 30 days, and the Kubernetes NetworkPolicy restricting ingress further reduces the attack surface by limiting who can even reach the affected containers. Combining low predicted exploitation with existing compensating controls justifies routine remediation timing rather than emergency action, letting the team patch the base image and redeploy during the normal maintenance cycle.

Why this answer

Despite high CVSS, the EPSS score indicates extremely low likelihood of exploitation in the wild. The business context and compensating controls (network policies) reduce risk. Therefore, remediation can be scheduled in normal patch cycle.

123
MCQhard

A security team is scanning container images with Trivy and finds a vulnerability with CVSS v3.1 vector AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H. The vulnerability exists in a container running as a privileged container on a Kubernetes cluster. The team is prioritizing based on risk. Given the CVSS vector, which factor most significantly reduces the likelihood of exploitation in this context?

A.Attack Vector: Local
B.Privileges Required: High
C.Attack Complexity: High
D.User Interaction: None
AnswerA

An Attack Vector of Local (AV:L) significantly reduces the exploitability score because the attacker cannot exploit the vulnerability over the network. They must already possess local shell access, console access, or the ability to execute code locally on the container or host, creating a major barrier to entry compared to Network-based attacks.

Why this answer

AV:L (Local) means the attacker must have local access to exploit. AC:H (High) and PR:H (High) are also limiting, but the attack vector being local means remote exploitation is not possible, which is a strong limiting factor. However, the question asks 'most significantly reduces the likelihood'.

While local access is limiting, Attack Complexity High also reduces likelihood. But AV:L is more significant because it restricts the attack source. In the context of a container, local access might be more achievable, but still the vector shows it's not remotely exploitable.

The best answer is Attack Vector: Local.

124
MCQeasy

A security analyst is configuring a container image scanning tool to identify vulnerabilities in a Docker image before deployment. Which of the following tools is commonly used for container image scanning?

A.Metasploit
B.Nmap
C.Wireshark
D.Trivy
AnswerD

Trivy is an open-source vulnerability scanner specifically designed for containers and other cloud-native targets. It quickly scans container images, filesystems, and Git repositories to detect known vulnerabilities (CVEs), misconfigurations, and leaked secrets, making it ideal for integration into CI/CD pipelines.

Why this answer

Trivy is a popular open-source container image vulnerability scanner. It is widely used for scanning Docker images for known vulnerabilities.

← PreviousPage 2 of 2 · 124 questions total

Ready to test yourself?

Try a timed practice session using only Cysa Vulnerability Management questions.