A system used to rate and prioritize vulnerabilities based on severity.
What is the Common Vulnerability Scoring System (CVSS)?
The software that runs a virtual machine?
What is a hypervisor?
A cybersecurity analyst uses this footprinting tool to gather information about a domain, including its IP address, location, and server details.
What is Whois?
An organization may seek guidance from this organization to ensure it meets the requirements of the Federal Information Security Modernization Act (FISMA).
What is the National Institute of Standards and Technology (NIST)?
This standard is used for sending log messages to a central logging server.
What is Syslog?
A security analyst manually reviews a device’s source code and configuration files to identify vulnerabilities while the device is not running.
What is static analysis?
This technology starts a minimal operating system for a remote user to access.
Virtual desktop infrastructure (VDI)
This tool can help stakeholders understand how a mapped network prevents simulated attacks.
What is Maltego?
This standardization body offers a framework that covers personal data and privacy.
What is the International Organization for Standardization (ISO)?
This type of event data can include commands used and unsuccessful attempts to access resources.
What is user-level event data?
A critical part of this vulnerability management step is conducting a pre-assessment to evaluate the organization’s current security posture.
What is baseline creation?
A security team uses this authentication mechanism to reduce the risk of stolen credentials being used to access sensitive resources and privileged accounts.
What is privileged access management (PAM)?
This scanning tool can create diagrams of network configurations.
What is NetAuditor?
A cybersecurity analyst uses this resource to research a known vulnerability and find its severity score, impact rating, and information about available fixes.
What is the National Vulnerability Database (NVD)?
A company wants its security tools to inspect encrypted HTTPS traffic for threats before re-encrypting and forwarding it to the destination
What is SSL inspection?
Vulnerability likelihood, potential impact, and patch availability.
What are factors to consider when measuring risk?
A security analyst evaluates vulnerabilities based on the environment, asset criticality, and potential business impact rather than treating every situation the same.
What is zero trust?
Gathering specific information about individual devices or services on a network.
What is fingerprinting?
Two companies want to establish mutual understanding and communication methods without entering into a legally binding agreement.
What is a memorandum of understanding (MoU)?
This XML-based design style is used by identity providers to pass authorization credentials to service providers.
What is Security Assertion Markup Language (SAML)?
When considering the vulnerability management lifecycle, an anlyst has already idetified and orgaized the vulnerabilities and risks facing an organization. The analyst must now implement fixes like patches, hardening, and security controls to correct the vulnerabilities.
What is remediation?
An identity provider needs to pass authorization credentials to a service provider using an XML-based technology.
What is Security Assertion Markup Language (SAML)?
This vulnerability management assessment tool is described as a cloud-based service that keeps data in a private virtual database.
What is Qualys Vulnerability Management?
This agreement defines the services, responsibilities, and performance requirements between two parties and is legally binding
What is a service-level agreement (SLA)?
The state of being calm, peaceful, and relaxed, often describing a feeling of inner balance and tranquility.
What is zen?