Free CompTIA Cybersecurity Analyst (CySA+) practice — 6 questions on Vulnerability Management, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Vulnerability Management
A vulnerability management program identifies two findings: Finding A has a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) affecting an internal database server with no known public exploit code. Finding B has a CVSS v3.1 base score of 7.5 affecting an internet-facing web application, and threat intelligence confirms active weaponized exploitation in the wild targeting this exact CVE. Given limited remediation resources this cycle, which finding should be prioritized FIRST?
CVSS base score alone doesn't account for exploit availability, exposure, or threat intelligence context. Active exploitation combined with internet-facing exposure creates higher real-world risk than a higher base score with no known exploit and internal-only exposure — this is the core principle behind risk-based, context-aware prioritization.
Question 2 of 6 · Vulnerability Management
A security analyst must assess vulnerabilities on a network segment containing legacy SCADA controllers that are known to crash or hang when receiving unexpected packets during active scans. Which vulnerability assessment approach is MOST appropriate for this environment?
Passive scanning observes existing network traffic without sending intrusive probes, avoiding the crash risk in fragile OT/SCADA devices. This is the standard recommended approach for legacy industrial control environments.
Question 3 of 6 · Vulnerability Management
An analyst is reviewing a CVSS v3.1 vector string and needs to determine whether a successful exploit could allow an attacker to affect resources outside the vulnerable component itself, such as pivoting from a hypervisor to affect guest VMs. Which base metric and value combination indicates this condition?
The Scope (S) metric with value Changed (C) specifically models a vulnerability in one security authority impacting resources governed by a different security authority, such as a VM escape or hypervisor pivot scenario.
Question 4 of 6 · Vulnerability Management
Which statement BEST describes a key limitation of agent-based vulnerability scanning compared to credentialed network scanning?
Deploying, updating, and maintaining agent software across every endpoint is a well-documented operational overhead of agent-based scanning, unlike credentialed network scans which run remotely without requiring endpoint software installation.
Question 5 of 6 · Vulnerability Management
A web application vulnerability scan reports that authenticated users can modify the numeric 'account_id' parameter in a URL to view or edit other customers' order records without authorization. Which control BEST remediates this specific vulnerability class?
This describes an Insecure Direct Object Reference (IDOR), a broken access control vulnerability. The correct fix is enforcing server-side object-level authorization checks on every request, rather than relying on obscurity or transport security.
Question 6 of 6 · Vulnerability Management
A vulnerability scan identifies a critical CVE on a legacy manufacturing control system. The vendor has confirmed no patch will ever be released because the system is end-of-life, and replacing it is not feasible for 18 months due to budget cycles. The organization's patching SLA requires critical vulnerabilities to be remediated within 15 days. Which action is MOST appropriate?
When patching is infeasible, standard vulnerability management practice calls for implementing compensating controls to reduce residual risk, combined with formal, documented risk acceptance and appropriate executive approval — satisfying governance requirements while acknowledging the SLA cannot be met as originally defined.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.