Vulnerability Mgmt (CVE/CVSS) interview questions

45 real Vulnerability Mgmt (CVE/CVSS) questions from the Security bank, as asked in Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd — free to start.

1. What is CVE?

Junior
  1. A.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  2. B.ranking remediation by combining severity, exploitability, and asset/business context
  3. C.Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  4. D.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
Reveal the answer + AI explanation — free account

3. Which statement is correct?

Junior
  1. A.CVE — a reported finding that is not actually a real vulnerability
  2. B.CVE — ranking remediation by combining severity, exploitability, and asset/business context
  3. C.CVE — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  4. D.CVE — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
Reveal the answer + AI explanation — free account

4. What is CVSS?

Junior
  1. A.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  2. B.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  3. C.Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  4. D.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
Reveal the answer + AI explanation — free account

6. Which statement is correct?

Junior
  1. A.CVSS — ranking remediation by combining severity, exploitability, and asset/business context
  2. B.CVSS — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  3. C.CVSS — reducing the risk or impact of a vulnerability without fully eliminating it
  4. D.CVSS — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
Reveal the answer + AI explanation — free account

7. What is Vulnerability?

Junior
  1. A.a weakness in a system that an attacker can exploit to compromise security
  2. B.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  3. C.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
  4. D.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
Reveal the answer + AI explanation — free account

9. Which statement is correct?

Junior
  1. A.Vulnerability — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  2. B.Vulnerability — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  3. C.Vulnerability — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  4. D.Vulnerability — a weakness in a system that an attacker can exploit to compromise security
Reveal the answer + AI explanation — free account

10. What is Patch management?

Junior
  1. A.severity from intrinsic characteristics of a vulnerability, independent of environment or time
  2. B.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  3. C.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  4. D.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
Reveal the answer + AI explanation — free account

12. Which statement is correct?

Junior
  1. A.Patch management — process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  2. B.Patch management — ranking remediation by combining severity, exploitability, and asset/business context
  3. C.Patch management — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  4. D.Patch management — a weakness in a system that an attacker can exploit to compromise security
Reveal the answer + AI explanation — free account

13. What is Exploit?

Junior
  1. A.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  2. B.Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
  3. C.code or technique that takes advantage of a vulnerability to cause unintended behavior
  4. D.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
Reveal the answer + AI explanation — free account

15. Which statement is correct?

Junior
  1. A.Exploit — code or technique that takes advantage of a vulnerability to cause unintended behavior
  2. B.Exploit — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  3. C.Exploit — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  4. D.Exploit — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
Reveal the answer + AI explanation — free account

16. What is CWE?

Junior
  1. A.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
  2. B.a weakness in a system that an attacker can exploit to compromise security
  3. C.reducing the risk or impact of a vulnerability without fully eliminating it
  4. D.severity from intrinsic characteristics of a vulnerability, independent of environment or time
Reveal the answer + AI explanation — free account

18. Which statement is correct?

Junior
  1. A.CWE — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  2. B.CWE — Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
  3. C.CWE — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  4. D.CWE — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
Reveal the answer + AI explanation — free account

19. What is CVSS base score?

Mid
  1. A.severity from intrinsic characteristics of a vulnerability, independent of environment or time
  2. B.Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  3. C.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  4. D.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
Reveal the answer + AI explanation — free account

21. Which statement is correct?

Mid
  1. A.CVSS base score — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
  2. B.CVSS base score — severity from intrinsic characteristics of a vulnerability, independent of environment or time
  3. C.CVSS base score — code or technique that takes advantage of a vulnerability to cause unintended behavior
  4. D.CVSS base score — reducing the risk or impact of a vulnerability without fully eliminating it
Reveal the answer + AI explanation — free account

22. What is Attack vector (CVSS)?

Mid
  1. A.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  2. B.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
  3. C.a reported finding that is not actually a real vulnerability
  4. D.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
Reveal the answer + AI explanation — free account

24. Which statement is correct?

Mid
  1. A.Attack vector (CVSS) — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  2. B.Attack vector (CVSS) — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  3. C.Attack vector (CVSS) — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  4. D.Attack vector (CVSS) — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
Reveal the answer + AI explanation — free account

25. What is False positive?

Mid
  1. A.code or technique that takes advantage of a vulnerability to cause unintended behavior
  2. B.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
  3. C.a reported finding that is not actually a real vulnerability
  4. D.severity from intrinsic characteristics of a vulnerability, independent of environment or time
Reveal the answer + AI explanation — free account

27. Which statement is correct?

Mid
  1. A.False positive — a reported finding that is not actually a real vulnerability
  2. B.False positive — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  3. C.False positive — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
  4. D.False positive — reducing the risk or impact of a vulnerability without fully eliminating it
Reveal the answer + AI explanation — free account

28. What is Remediation?

Mid
  1. A.a weakness in a system that an attacker can exploit to compromise security
  2. B.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
  3. C.fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  4. D.a reported finding that is not actually a real vulnerability
Reveal the answer + AI explanation — free account

30. Which statement is correct?

Mid
  1. A.Remediation — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
  2. B.Remediation — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
  3. C.Remediation — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
  4. D.Remediation — reducing the risk or impact of a vulnerability without fully eliminating it
Reveal the answer + AI explanation — free account

Showing 30 of 45 Vulnerability Mgmt (CVE/CVSS) questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Answers, AI explanations, and a scored voice mock interview

Sign up free to check your answers with explanations, ask the AI tutor anything on any question, and take one full AI mock interview — scored like a real panel.

Practice Vulnerability Mgmt (CVE/CVSS) free