Vulnerability Mgmt (CVE/CVSS) interview questions

45 Vulnerability Mgmt (CVE/CVSS) questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is CVE?

Junior
  1. A.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  2. B.ranking remediation by combining severity, exploitability, and asset/business context
  3. C.Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  4. D.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability

Answer + AI explanation with Pro

2. Which term means: "Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability"?

Junior
  1. A.EPSS
  2. B.Mitigation
  3. C.False positive
  4. D.CVE

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.CVE — a reported finding that is not actually a real vulnerability
  2. B.CVE — ranking remediation by combining severity, exploitability, and asset/business context
  3. C.CVE — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  4. D.CVE — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability

Answer + AI explanation with Pro

4. What is CVSS?

Junior
  1. A.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  2. B.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  3. C.Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  4. D.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild

Answer + AI explanation with Pro

5. Which term means: "Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability"?

Junior
  1. A.CWE
  2. B.Exploit
  3. C.CVSS
  4. D.Attack vector (CVSS)

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.CVSS — ranking remediation by combining severity, exploitability, and asset/business context
  2. B.CVSS — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  3. C.CVSS — reducing the risk or impact of a vulnerability without fully eliminating it
  4. D.CVSS — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability

Answer + AI explanation with Pro

7. What is Vulnerability?

Junior
  1. A.a weakness in a system that an attacker can exploit to compromise security
  2. B.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  3. C.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
  4. D.process of acquiring, testing, and deploying software updates to remediate vulnerabilities

Answer + AI explanation with Pro

8. Which term means: "a weakness in a system that an attacker can exploit to compromise security"?

Junior
  1. A.CVSS
  2. B.Vulnerability
  3. C.Remediation
  4. D.Coordinated disclosure

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Vulnerability — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  2. B.Vulnerability — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  3. C.Vulnerability — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  4. D.Vulnerability — a weakness in a system that an attacker can exploit to compromise security

Answer + AI explanation with Pro

10. What is Patch management?

Junior
  1. A.severity from intrinsic characteristics of a vulnerability, independent of environment or time
  2. B.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  3. C.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  4. D.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical

Answer + AI explanation with Pro

11. Which term means: "process of acquiring, testing, and deploying software updates to remediate vulnerabilities"?

Junior
  1. A.Patch management
  2. B.CVE
  3. C.Vulnerability
  4. D.KEV catalog

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Patch management — process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  2. B.Patch management — ranking remediation by combining severity, exploitability, and asset/business context
  3. C.Patch management — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  4. D.Patch management — a weakness in a system that an attacker can exploit to compromise security

Answer + AI explanation with Pro

13. What is Exploit?

Junior
  1. A.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  2. B.Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  3. C.code or technique that takes advantage of a vulnerability to cause unintended behavior
  4. D.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities

Answer + AI explanation with Pro

14. Which term means: "code or technique that takes advantage of a vulnerability to cause unintended behavior"?

Junior
  1. A.Coordinated disclosure
  2. B.Risk-based prioritization
  3. C.Exploit
  4. D.CWE

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Exploit — code or technique that takes advantage of a vulnerability to cause unintended behavior
  2. B.Exploit — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  3. C.Exploit — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  4. D.Exploit — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public

Answer + AI explanation with Pro

16. What is CWE?

Junior
  1. A.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
  2. B.a weakness in a system that an attacker can exploit to compromise security
  3. C.reducing the risk or impact of a vulnerability without fully eliminating it
  4. D.severity from intrinsic characteristics of a vulnerability, independent of environment or time

Answer + AI explanation with Pro

17. Which term means: "Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities"?

Junior
  1. A.False positive
  2. B.CVSS
  3. C.Risk-based prioritization
  4. D.CWE

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.CWE — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  2. B.CWE — Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
  3. C.CWE — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  4. D.CWE — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability

Answer + AI explanation with Pro

19. What is CVSS base score?

Mid
  1. A.severity from intrinsic characteristics of a vulnerability, independent of environment or time
  2. B.Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  3. C.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  4. D.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities

Answer + AI explanation with Pro

20. Which term means: "severity from intrinsic characteristics of a vulnerability, independent of environment or time"?

Mid
  1. A.Mitigation
  2. B.CVSS base score
  3. C.Patch management
  4. D.CWE

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.CVSS base score — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
  2. B.CVSS base score — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  3. C.CVSS base score — code or technique that takes advantage of a vulnerability to cause unintended behavior
  4. D.CVSS base score — reducing the risk or impact of a vulnerability without fully eliminating it

Answer + AI explanation with Pro

22. What is Attack vector (CVSS)?

Mid
  1. A.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  2. B.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  3. C.a reported finding that is not actually a real vulnerability
  4. D.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical

Answer + AI explanation with Pro

23. Which term means: "metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical"?

Mid
  1. A.Mitigation
  2. B.Patch management
  3. C.Attack vector (CVSS)
  4. D.Risk-based prioritization

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Attack vector (CVSS) — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  2. B.Attack vector (CVSS) — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  3. C.Attack vector (CVSS) — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  4. D.Attack vector (CVSS) — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical

Answer + AI explanation with Pro

25. What is False positive?

Mid
  1. A.code or technique that takes advantage of a vulnerability to cause unintended behavior
  2. B.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
  3. C.a reported finding that is not actually a real vulnerability
  4. D.severity from intrinsic characteristics of a vulnerability, independent of environment or time

Answer + AI explanation with Pro

26. Which term means: "a reported finding that is not actually a real vulnerability"?

Mid
  1. A.CVE
  2. B.False positive
  3. C.CWE
  4. D.KEV catalog

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.False positive — a reported finding that is not actually a real vulnerability
  2. B.False positive — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  3. C.False positive — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  4. D.False positive — reducing the risk or impact of a vulnerability without fully eliminating it

Answer + AI explanation with Pro

28. What is Remediation?

Mid
  1. A.a weakness in a system that an attacker can exploit to compromise security
  2. B.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  3. C.fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  4. D.a reported finding that is not actually a real vulnerability

Answer + AI explanation with Pro

29. Which term means: "fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component"?

Mid
  1. A.Coordinated disclosure
  2. B.Patch management
  3. C.Remediation
  4. D.CVSS

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.Remediation — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  2. B.Remediation — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  3. C.Remediation — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  4. D.Remediation — reducing the risk or impact of a vulnerability without fully eliminating it

Answer + AI explanation with Pro

Showing 30 of 45 Vulnerability Mgmt (CVE/CVSS) questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Vulnerability Mgmt (CVE/CVSS) question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers