1. What is CVE ? Junior A. responsibly reporting a vulnerability to the vendor and allowing time to patch before going public B. ranking remediation by combining severity, exploitability, and asset/business context C. Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon D. Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability Reveal the answer + AI explanation — free account
2. Which term means: "Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability"? Junior A. EPSS B. Mitigation C. False positive D. CVE Reveal the answer + AI explanation — free account
3. Which statement is correct? Junior A. CVE — a reported finding that is not actually a real vulnerability B. CVE — ranking remediation by combining severity, exploitability, and asset/business context C. CVE — severity from intrinsic characteristics of a vulnerability, independent of environment or time D. CVE — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability Reveal the answer + AI explanation — free account
4. What is CVSS ? Junior A. process of acquiring, testing, and deploying software updates to remediate vulnerabilities B. Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability C. Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability D. CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild Reveal the answer + AI explanation — free account
5. Which term means: "Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability"? Junior A. CWE B. Exploit C. CVSS D. Attack vector (CVSS) Reveal the answer + AI explanation — free account
6. Which statement is correct? Junior A. CVSS — ranking remediation by combining severity, exploitability, and asset/business context B. CVSS — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon C. CVSS — reducing the risk or impact of a vulnerability without fully eliminating it D. CVSS — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability Reveal the answer + AI explanation — free account
7. What is Vulnerability ? Junior A. a weakness in a system that an attacker can exploit to compromise security B. CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild C. Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities D. process of acquiring, testing, and deploying software updates to remediate vulnerabilities Reveal the answer + AI explanation — free account
8. Which term means: "a weakness in a system that an attacker can exploit to compromise security"? Junior A. CVSS B. Vulnerability C. Remediation D. Coordinated disclosure Reveal the answer + AI explanation — free account
9. Which statement is correct? Junior A. Vulnerability — Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon B. Vulnerability — severity from intrinsic characteristics of a vulnerability, independent of environment or time C. Vulnerability — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild D. Vulnerability — a weakness in a system that an attacker can exploit to compromise security Reveal the answer + AI explanation — free account
10. What is Patch management ? Junior A. severity from intrinsic characteristics of a vulnerability, independent of environment or time B. process of acquiring, testing, and deploying software updates to remediate vulnerabilities C. responsibly reporting a vulnerability to the vendor and allowing time to patch before going public D. metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical Reveal the answer + AI explanation — free account
11. Which term means: "process of acquiring, testing, and deploying software updates to remediate vulnerabilities"? Junior A. Patch management B. CVE C. Vulnerability D. KEV catalog Reveal the answer + AI explanation — free account
12. Which statement is correct? Junior A. Patch management — process of acquiring, testing, and deploying software updates to remediate vulnerabilities B. Patch management — ranking remediation by combining severity, exploitability, and asset/business context C. Patch management — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability D. Patch management — a weakness in a system that an attacker can exploit to compromise security Reveal the answer + AI explanation — free account
13. What is Exploit ? Junior A. process of acquiring, testing, and deploying software updates to remediate vulnerabilities B. Exploit Prediction Scoring System estimating the probability a vulnerability will be exploited soon C. code or technique that takes advantage of a vulnerability to cause unintended behavior D. Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities Reveal the answer + AI explanation — free account
14. Which term means: "code or technique that takes advantage of a vulnerability to cause unintended behavior"? Junior A. Coordinated disclosure B. Risk-based prioritization C. Exploit D. CWE Reveal the answer + AI explanation — free account
15. Which statement is correct? Junior A. Exploit — code or technique that takes advantage of a vulnerability to cause unintended behavior B. Exploit — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability C. Exploit — severity from intrinsic characteristics of a vulnerability, independent of environment or time D. Exploit — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public Reveal the answer + AI explanation — free account
16. What is CWE ? Junior A. Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities B. a weakness in a system that an attacker can exploit to compromise security C. reducing the risk or impact of a vulnerability without fully eliminating it D. severity from intrinsic characteristics of a vulnerability, independent of environment or time Reveal the answer + AI explanation — free account
17. Which term means: "Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities"? Junior A. False positive B. CVSS C. Risk-based prioritization D. CWE Reveal the answer + AI explanation — free account
18. Which statement is correct? Junior A. CWE — severity from intrinsic characteristics of a vulnerability, independent of environment or time B. CWE — Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities C. CWE — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component D. CWE — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability Reveal the answer + AI explanation — free account
19. What is CVSS base score ? Mid A. severity from intrinsic characteristics of a vulnerability, independent of environment or time B. Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability C. CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild D. Common Weakness Enumeration, a catalog of software weakness types underlying vulnerabilities Reveal the answer + AI explanation — free account
20. Which term means: "severity from intrinsic characteristics of a vulnerability, independent of environment or time"? Mid A. Mitigation B. CVSS base score C. Patch management D. CWE Reveal the answer + AI explanation — free account
21. Which statement is correct? Mid A. CVSS base score — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical B. CVSS base score — severity from intrinsic characteristics of a vulnerability, independent of environment or time C. CVSS base score — code or technique that takes advantage of a vulnerability to cause unintended behavior D. CVSS base score — reducing the risk or impact of a vulnerability without fully eliminating it Reveal the answer + AI explanation — free account
22. What is Attack vector (CVSS) ? Mid A. responsibly reporting a vulnerability to the vendor and allowing time to patch before going public B. process of acquiring, testing, and deploying software updates to remediate vulnerabilities C. a reported finding that is not actually a real vulnerability D. metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical Reveal the answer + AI explanation — free account
23. Which term means: "metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical"? Mid A. Mitigation B. Patch management C. Attack vector (CVSS) D. Risk-based prioritization Reveal the answer + AI explanation — free account
24. Which statement is correct? Mid A. Attack vector (CVSS) — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild B. Attack vector (CVSS) — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public C. Attack vector (CVSS) — Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability D. Attack vector (CVSS) — metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical Reveal the answer + AI explanation — free account
25. What is False positive ? Mid A. code or technique that takes advantage of a vulnerability to cause unintended behavior B. metric describing how a vulnerability is reached: Network, Adjacent, Local, or Physical C. a reported finding that is not actually a real vulnerability D. severity from intrinsic characteristics of a vulnerability, independent of environment or time Reveal the answer + AI explanation — free account
26. Which term means: "a reported finding that is not actually a real vulnerability"? Mid A. CVE B. False positive C. CWE D. KEV catalog Reveal the answer + AI explanation — free account
27. Which statement is correct? Mid A. False positive — a reported finding that is not actually a real vulnerability B. False positive — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component C. False positive — Common Vulnerability Scoring System producing a 0-10 severity score for a vulnerability D. False positive — reducing the risk or impact of a vulnerability without fully eliminating it Reveal the answer + AI explanation — free account
28. What is Remediation ? Mid A. a weakness in a system that an attacker can exploit to compromise security B. Common Vulnerabilities and Exposures, a unique public identifier for a specific known vulnerability C. fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component D. a reported finding that is not actually a real vulnerability Reveal the answer + AI explanation — free account
29. Which term means: "fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component"? Mid A. Coordinated disclosure B. Patch management C. Remediation D. CVSS Reveal the answer + AI explanation — free account
30. Which statement is correct? Mid A. Remediation — CISA's Known Exploited Vulnerabilities list of CVEs confirmed to be exploited in the wild B. Remediation — fixing a vulnerability, e.g. by patching, reconfiguring, or removing the affected component C. Remediation — responsibly reporting a vulnerability to the vendor and allowing time to patch before going public D. Remediation — reducing the risk or impact of a vulnerability without fully eliminating it Reveal the answer + AI explanation — free accountShowing 30 of 45 Vulnerability Mgmt (CVE/CVSS) questions — the full set, with answers, explanations and an AI tutor on every question, is inside.