Vulnerability Management
CS0-004 · 78 questions
- A vulnerability analyst must verify patch levels, local service configurations, and installed software on 200 internal Windows servers. The scanner can run from the internal network, but the team also wants to avoid unnecessary external exposure. Which scanning method should the analyst implement?
- An enterprise SOC needs to determine what internet-facing services and externally reachable weaknesses an attacker could discover without valid credentials. Which vulnerability scanning method should be implemented?
- A web application team asks the vulnerability analyst to identify runtime input-validation and session-management flaws in a running portal. The analyst does not have source code access. Which scanning method should be implemented?
- A DevOps team builds Linux container images in a CI/CD pipeline and pushes them to a private registry. Security wants to catch vulnerable base-image packages and application dependencies before images reach production. Which vulnerability scanning method best addresses risk inherited from the container layer?
- A SOC receives a request from the cloud team to assess newly deployed IaaS workloads for misconfigured IAM roles, public storage buckets, and unnecessary network exposure. The scanner supports operating system, network, container, and cloud API methods. Which method should the analyst select to evaluate the cloud control-plane configuration and exposed resources?
- A SOC engineer must determine whether servers have drifted from an approved CIS hardening benchmark, not whether they contain unpatched software. Which scanning method should be implemented?
- Your SOC scans an on-prem subnet reliably, but remote contractors use laptops that connect intermittently through VPN and rarely appear in network scans. A manager asks for vulnerability coverage on those endpoints without adding new VPN access. Which scanning method should implement?
- A hospital SOC must inventory medical imaging hosts in a restricted VLAN. Active scanning is prohibited because it could interrupt imaging sessions, and the hosts rarely respond to ICMP. The team has NetFlow, DHCP logs, and EDR telemetry. Which discovery method should the analyst use to build an accurate asset inventory?
- A SOC receives a report that a production SQL database may allow excessive application privileges, anonymous authentication, and exposed schema paths. The analyst must assess the database configuration rather than only host patch status. Which scanning method should be implemented?
- A SOC analyst must scan a sensitive production service that cannot tolerate performance degradation. Which scanning approach should be scheduled?
- A vulnerability scan is scheduled across an IaaS subnet that contains a legacy host known to lock up when contacted by active checks. The system cannot be patched soon, but the SOC still needs visibility into its risk. Which scanning approach should be used to protect the host while maintaining coverage?
- A SOC analyst is configuring credentialed vulnerability scans for Windows and Linux servers in a hybrid estate. The scanner must verify patch levels and software inventory, but the security team forbids administrative credentials for scanning. Which credential scope should be used?
- A custom web application uses several open-source libraries. The host OS vulnerability scan is clean, but the application team suspects a vulnerable component is bundled inside the application package. Which scanning method should the analyst request?
- An enterprise SOC supports an OT segment with legacy PLCs and environmental sensors used in a manufacturing line. Availability and safety are critical, and the scanner's active probes previously caused a controller to reboot. Management asks for vulnerability visibility without introducing additional disruption. Which vulnerability scanning method should the analyst implement first?
- A SOC analyst receives a report that a public web app may have hidden administrative endpoints returning sensitive data. Host vulnerability scans show no known CVEs on the server. Which scanning method should be used to find undocumented or exposed API routes?
- A developer asks your vulnerability team to review a new web application before it is deployed. The application is not running yet, but the team wants to catch insecure coding patterns such as unsafe input handling and hardcoded secrets. Which vulnerability scanning method is most appropriate?
- An analyst must verify whether a Windows server is missing Microsoft security updates and whether local audit policy settings are configured correctly. The scan must check installed patches and registry settings without relying on network services. Which vulnerability scanning method should be used?
- A vulnerability analyst needs to confirm which TCP and UDP ports on a database server are reachable from the analyst's scanning subnet and whether services respond to probes. Which scanning method should be used?
- A SOC analyst reviews a scan report showing an Apache server exposes version details, enables TRACE, and omits X-Content-Type-Options and X-Frame-Options. The application code team says the web app itself has no code defects. Which vulnerability scanning method should the analyst request to validate these findings?
- Your SOC receives an alert that a vulnerable library was found in a container image deployed from the private registry. The image was built three months ago, and the registry holds many older images awaiting rollout. You need to identify which stored images are vulnerable before they are deployed. Which scanning method should you implement?
- An unauthenticated scan flags missing SMB signing on a Windows file server using only banner and version heuristics. A later authenticated local check confirms SMB signing is enforced. How should the analyst classify the original scan result?
- A scanner report shows the same CVE on 600 hosts, including domain controllers, web servers, and lab VMs. Which remediation ranking approach is best?
- A vulnerability report shows a web application flaw with the vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N. Which statement best explains the base-score drivers?
- A vulnerability scanner exports a CVSS v4 finding for an internal file server. The base score is critical, but exploit maturity is unproven and threat intelligence confidence is low. What should the analyst do?
- A vulnerability scan result for a web server lists a CVE identifier, a CWE identifier, and a CPE identifier. The analyst must explain what each identifier tells them before prioritizing remediation. Which mapping is correct?
- A vulnerability scanner reports a Critical CVSS 9.8 rating for a remote code execution flaw on a domain controller. The DC is only reachable from a restricted management VLAN, requires authenticated access, and no public exploit is observed in your threat feed. What is the best way to use the scanner result?
- A vulnerability scan reports CVE-1234 as Critical with CVSS 9.8 but no known exploit or threat actor activity, while CVE-5678 is High with CVSS 7.5 but has a public exploit and active threat-actor use. After feed enrichment, how should the analyst refine the scanner finding?
- A vulnerability scanner reports that an internal web service is using an expired TLS certificate. Which classification best describes the finding?
- A vulnerability scan returns a finding with plugin metadata stating severity: informational, category: policy check, and no CVE. The scanner also notes it does not confirm remote code execution. As an analyst, what should you do with this finding?
- An analyst compares two scans of the same Windows server. The authenticated scan lists dozens of missing patches and vulnerable applications, while the unauthenticated scan only reports exposed RDP and SMB. Which conclusion is best supported by the scan output?
- A scanner report flags a Windows host because local password policy allows 4-character passwords and no account lockout. The finding cites no CVE, affected package version, or exploit code. How should an analyst classify this finding for remediation?
- A patch report shows a missing security update on an internal server. The vulnerability scanner also confirms the affected service is reachable from the analyst's network. Which conclusion is best supported by the output?
- A web scanner reports reflected cross-site scripting in a login form. Which weakness category best explains the finding?
- A cloud vulnerability scan reports a storage bucket as publicly readable, with no authentication required, and confirms it contains exported SIEM events. The bucket host shows no missing patches or vulnerable services. Which finding classification is most accurate?
- A vulnerability scan reports several CVEs in a running container. The analyst traces them to packages inherited from the base image, and the container is ephemeral. Which remediation is most appropriate?
- A vulnerability scan of a server subnet returns zero findings. The scan report shows no credentials used, and firewall logs show the scanner's IP was denied to TCP 445 and 3389. What should the analyst conclude first?
- An authenticated web-server scan flags several weak TLS cipher suites, including export-grade and CBC modes without AEAD. The analyst must classify the finding for remediation. How should the finding be interpreted?
- A vulnerability scan of an internal switch management interface reports that vendor default administrator credentials are still enabled. The interface is reachable only from a restricted SOC VLAN. How should the analyst classify this finding?
- A vulnerability scan returns a finding on legacy file servers: 'SMBv1 enabled.' The servers still host read-only shares for an application that cannot be updated. Which interpretation best describes the risk indicated by this finding?
- A vulnerability scanner reports CVE-2025-1234 on an internet-facing web server. A threat intelligence feed states that the same CVE is being actively exploited in the wild, but the scanner did not confirm a successful exploit. How should the analyst treat the finding?
- An enterprise SOC receives a scanner report: a high-severity authentication bypass CVE affects an internet-facing SSO gateway used by privileged admins. The gateway has no compensating controls and sits in a DMZ. Which remediation decision best aligns with vulnerability prioritization?
- A vulnerability scanner reports a medium-severity CVE on an internet-facing web server. Threat intelligence confirms the CVE is being actively exploited in the wild, but internal logs show no compromise indicators. What should the vulnerability analyst do?
- An analyst reviews a vulnerability scan and sees a critical finding on a database server that stores regulated customer data. The server is internal, heavily used by customer service, and has compensating network segmentation. Which factor should most strongly drive the remediation ranking?
- A scanner reports a critical web server vulnerability with a public exploit and the service is reachable from the internet. The server hosts an internal application behind a WAF. Which remediation action is most appropriate?
- An analyst reviews a vulnerability scanner report. A medium CVSS vulnerability affects an isolated internal workstation used only for local testing, with no sensitive data and no outbound internet access. Which remediation decision is best?
- An internet-facing web application has a CVSS 9.1 vulnerability. The vulnerability scanner cannot confirm exploitability, but the WAF has a virtual patch blocking known exploit traffic. How should the analyst adjust risk priority?
- A critical vulnerability on a production web server has a vendor patch, but the change must be regression-tested before release. The service must remain available during business hours. Which patch action best balances risk reduction with availability?
- A vulnerability scan finds a critical unpatched service on a legacy server that supports a revenue-critical application. The application owner states that applying the vendor patch will break production, and no safe workaround exists. What should the vulnerability analyst do first?
- A high-volume vulnerability scan returns a high-severity finding on an application server. The analyst suspects a false positive because the banner and installed package do not match the scanner’s assumption. What should the analyst do before assigning remediation effort?
- A vulnerability scan reports CVE-2025-1234 on 42 web servers. The scanner creates one ticket per host, each assigned to a different application team. The tickets share the same CVE, affected package, and CVSS score, but differ only by hostname. What should the analyst do first to prioritize remediation efficiently?
- A hybrid enterprise scans on-prem servers and IaaS workloads. Findings include critical internet-facing web vulnerabilities, high-severity internal server issues, and low-severity internal workstation issues. Business impact includes customer-facing outage risk and regulated data exposure. Which remediation SLA schedule best assigns due dates based on risk tier and business impact?
- An analyst finds a critical vulnerability in an internet-facing service. The vendor has not released a patch, but the vendor advisory lists a configuration change that reduces exposure. What should the vulnerability management team do first?
- A triage queue contains findings from a network scanner, cloud CSPM, and container scanner. Before remediation work starts, what should the analyst do first?
- A vulnerability scanner report lists an unpatched web application flaw with base score 7.5. Threat intelligence now shows exploit code maturity changed from Unproven to Functional, and active exploitation attempts are appearing in honeypot logs. Which action should the vulnerability analyst take first?
- A cloud vulnerability scan reports multiple storage misconfigurations across a hybrid estate. Some buckets contain regulated data, others contain non-sensitive files; some are public, others private. Which prioritization approach is most appropriate for remediation planning?
- A plant historian in the OT network has a known critical vulnerability, but the vendor says no patch will be released and the asset cannot be taken offline. The vulnerability analyst needs to reduce risk now. Which action should be prioritized?
- A vulnerability scanner reports the same vulnerable open-source library in five web applications. The applications are owned by different teams, but all depend on the same shared platform package. Which remediation approach is most efficient?
- A vulnerability on a jump host used by administrators to reach production servers scores CVSS 8.1. The host has no internet exposure, but it stores SSH keys and administrative credentials for many systems. Which prioritization rationale best fits the risk?
- A compliance audit is due in 30 days. A medium-severity vulnerability is found on a noncritical legacy server. The regulation requires remediation of all findings in this category before the audit. Which prioritization approach is most appropriate?
- An analyst reviews a vulnerability-management program and notes that critical CVEs are patched within 14 days to stop attackers from using published exploits against internet-facing servers. Which control type does this patching activity best represent?
- Your SOC runs credentialed vulnerability scans nightly against hybrid servers. The scanner finds missing patches, weak ciphers, and exposed ports, but it does not stop the vulnerable systems from being attacked. In control-type terms, what role does this scanning primarily fulfill?
- A SOC analyst confirms a critical privilege-escalation vulnerability on a file server. After a risk assessment, administrators apply the vendor patch, restart the service, and validate that the vulnerable code path no longer executes. Which control type best describes this action?
- A critical remote code execution vulnerability is found on an unsupported legacy server, and the vendor cannot provide a patch. Which action should the analyst recommend first?
- A SOC analyst learns that a legacy internal service has an unpatchable vulnerability and no business owner needs it anymore. The team decommissions the service and removes it from the network. Which risk response does this represent?
- A vulnerability scanner reports a critical remote code execution flaw in an internet-facing web server. During the next maintenance window, the operations team applies the vendor patch and restarts the service. Which risk response has been applied?
- A managed service provider assumes contractual responsibility for patching and remediation SLAs for externally exposed web servers, including penalties for missed deadlines. Which risk response best describes this arrangement?
- A legacy web application cannot be patched without breaking a revenue system. After compensating controls are in place, an executive signs a memo stating the remaining exposure is acceptable for 18 months. Which vulnerability response best matches this decision?
- An analyst finds a critical vulnerability in a production server. The scanner report and change ticket exist, but management asks for evidence that the finding is being handled under the organization's risk process. Which artifact best demonstrates governed vulnerability response?
- A legacy application server has a critical vulnerability, but patching breaks a vendor-supported workflow. The business asks for a risk acceptance so the server can remain online. The analyst proposes compensating controls such as network segmentation and virtual patching. What is the best way to document the vulnerability response?
- An asset owner reports that a critical CVE on an internet-facing web server has been patched. The SOC analyst needs to confirm the vulnerability no longer exists before closing the remediation ticket. Which action best validates control effectiveness?
- A SOC analyst reviews a server build template that disables unused services, removes legacy protocols, and enforces secure defaults before deployment. The organization uses the template to reduce exposure before an attacker can exploit weak configurations. Which control type best describes this template?
- A legacy IIS server has a critical unpatched remote code execution vulnerability, and the application team cannot take it offline for patching this week. Which compensating control best reduces exploitability while the fix is pending?
- A SOC analyst notices a web application still contains a known input-validation flaw, but a WAF rule blocks the exploit path while a patch is scheduled. Which statement best describes the WAF's role?
- An analyst notices an unpatched web server receiving exploit attempts. The EDR agent generates alerts and captures process behavior, but the host remains unpatched. How should the EDR capability be classified in vulnerability response?
- A security analyst receives a governance policy that mandates weekly vulnerability scans of all production subnets and requires critical vulnerabilities to be remediated within seven days. The policy is approved by senior management and communicated to operations teams. How should the analyst classify this governance policy?
- A SOC analyst sees a CVSS 9.8 vulnerability on an internet-facing web server and a CVSS 7.4 vulnerability on the payroll database. The payroll system supports monthly employee payments and has no compensating controls. Which vulnerability should the analyst recommend remediating first?
- A critical vulnerability is found in a production web service. A vendor patch exists, but applying it requires a maintenance window. The service owner worries about downtime, and the security team wants the risk reduced quickly. Which approach best balances vulnerability closure with service availability?
- A vulnerability analyst triages findings in a hybrid SOC. Some systems have higher business value and exposure. Leadership has approved a risk appetite statement for acceptable exposure. What primarily determines how quickly a vulnerability finding must be remediated?