45 Vulnerability Mgmt (CVE/CVSS) questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
B.ranking remediation by combining severity, exploitability, and asset/business context
C.Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
D.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
Answer + AI explanation with Pro
2. Which term means: "Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability"?
Junior
A.EPSS
B.Mitigation
C.False positive
D.CVE
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.CVE — a reported finding that is not actually a real vulnerability
B.CVE — ranking remediation by combining severity, exploitability, and asset/business context
C.CVE — severity from intrinsic characteristics of a vulnerability, independent of environment or time
D.CVE — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
Answer + AI explanation with Pro
4. What is CVSS?
Junior
A.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
B.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
C.Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
D.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
Answer + AI explanation with Pro
5. Which term means: "Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability"?
Junior
A.CWE
B.Exploit
C.CVSS
D.Attack vector (CVSS)
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.CVSS — ranking remediation by combining severity, exploitability, and asset/business context
B.CVSS — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
C.CVSS — reducing the risk or impact of a vulnerability without fully eliminating it
D.CVSS — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
Answer + AI explanation with Pro
7. What is Vulnerability?
Junior
A.a weakness in a system that an attacker can exploit to compromise security
B.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
C.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
D.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
Answer + AI explanation with Pro
8. Which term means: "a weakness in a system that an attacker can exploit to compromise security"?
Junior
A.CVSS
B.Vulnerability
C.Remediation
D.Coordinated disclosure
Answer + AI explanation with Pro
9. Which statement is correct?
Junior
A.Vulnerability — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
B.Vulnerability — severity from intrinsic characteristics of a vulnerability, independent of environment or time
C.Vulnerability — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
D.Vulnerability — a weakness in a system that an attacker can exploit to compromise security
Answer + AI explanation with Pro
10. What is Patch management?
Junior
A.severity from intrinsic characteristics of a vulnerability, independent of environment or time
B.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
C.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
D.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
Answer + AI explanation with Pro
11. Which term means: "process of acquiring, testing, and deploying software updates to remediate vulnerabilities"?
Junior
A.Patch management
B.CVE
C.Vulnerability
D.KEV catalog
Answer + AI explanation with Pro
12. Which statement is correct?
Junior
A.Patch management — process of acquiring, testing, and deploying software updates to remediate vulnerabilities
B.Patch management — ranking remediation by combining severity, exploitability, and asset/business context
C.Patch management — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
D.Patch management — a weakness in a system that an attacker can exploit to compromise security
Answer + AI explanation with Pro
13. What is Exploit?
Junior
A.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
B.Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon
C.code or technique that takes advantage of a vulnerability to cause unintended behavior
D.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
Answer + AI explanation with Pro
14. Which term means: "code or technique that takes advantage of a vulnerability to cause unintended behavior"?
Junior
A.Coordinated disclosure
B.Risk-based prioritization
C.Exploit
D.CWE
Answer + AI explanation with Pro
15. Which statement is correct?
Junior
A.Exploit — code or technique that takes advantage of a vulnerability to cause unintended behavior
B.Exploit — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
C.Exploit — severity from intrinsic characteristics of a vulnerability, independent of environment or time
D.Exploit — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
Answer + AI explanation with Pro
16. What is CWE?
Junior
A.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
B.a weakness in a system that an attacker can exploit to compromise security
C.reducing the risk or impact of a vulnerability without fully eliminating it
D.severity from intrinsic characteristics of a vulnerability, independent of environment or time
Answer + AI explanation with Pro
17. Which term means: "Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities"?
Junior
A.False positive
B.CVSS
C.Risk-based prioritization
D.CWE
Answer + AI explanation with Pro
18. Which statement is correct?
Junior
A.CWE — severity from intrinsic characteristics of a vulnerability, independent of environment or time
B.CWE — Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
C.CWE — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
D.CWE — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
Answer + AI explanation with Pro
19. What is CVSS base score?
Mid
A.severity from intrinsic characteristics of a vulnerability, independent of environment or time
B.Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
C.CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
D.Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities
Answer + AI explanation with Pro
20. Which term means: "severity from intrinsic characteristics of a vulnerability, independent of environment or time"?
Mid
A.Mitigation
B.CVSS base score
C.Patch management
D.CWE
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.CVSS base score — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
B.CVSS base score — severity from intrinsic characteristics of a vulnerability, independent of environment or time
C.CVSS base score — code or technique that takes advantage of a vulnerability to cause unintended behavior
D.CVSS base score — reducing the risk or impact of a vulnerability without fully eliminating it
Answer + AI explanation with Pro
22. What is Attack vector (CVSS)?
Mid
A.responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
B.process of acquiring, testing, and deploying software updates to remediate vulnerabilities
C.a reported finding that is not actually a real vulnerability
D.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
Answer + AI explanation with Pro
23. Which term means: "metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical"?
Mid
A.Mitigation
B.Patch management
C.Attack vector (CVSS)
D.Risk-based prioritization
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.Attack vector (CVSS) — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
B.Attack vector (CVSS) — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
C.Attack vector (CVSS) — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
D.Attack vector (CVSS) — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
Answer + AI explanation with Pro
25. What is False positive?
Mid
A.code or technique that takes advantage of a vulnerability to cause unintended behavior
B.metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical
C.a reported finding that is not actually a real vulnerability
D.severity from intrinsic characteristics of a vulnerability, independent of environment or time
Answer + AI explanation with Pro
26. Which term means: "a reported finding that is not actually a real vulnerability"?
Mid
A.CVE
B.False positive
C.CWE
D.KEV catalog
Answer + AI explanation with Pro
27. Which statement is correct?
Mid
A.False positive — a reported finding that is not actually a real vulnerability
B.False positive — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
C.False positive — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability
D.False positive — reducing the risk or impact of a vulnerability without fully eliminating it
Answer + AI explanation with Pro
28. What is Remediation?
Mid
A.a weakness in a system that an attacker can exploit to compromise security
B.Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability
C.fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
D.a reported finding that is not actually a real vulnerability
Answer + AI explanation with Pro
29. Which term means: "fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component"?
Mid
A.Coordinated disclosure
B.Patch management
C.Remediation
D.CVSS
Answer + AI explanation with Pro
30. Which statement is correct?
Mid
A.Remediation — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild
B.Remediation — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component
C.Remediation — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public
D.Remediation — reducing the risk or impact of a vulnerability without fully eliminating it
Answer + AI explanation with Pro
Showing 30 of 45 Vulnerability Mgmt (CVE/CVSS) questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Vulnerability Mgmt (CVE/CVSS) question come with Pro.