MCQ Bank
Continuous monitoring feature of QULAYS is very useful for?
- A) Scanning of web application
- B) Vulnerability management of assets
- C) Checking compliance of CIS benchmarks
- D) Watching critical changes
Which team tests the patches in test environment in vulnerability management process?
- A) Information security team
- B) IT operations team
- C) Risk & compliance team
- D) Business team
Which of the following modules are displayed on home screen of qualys trial version?
- A) Vulnerability management and policy compliance
- B) File integrity monitoring
- C) Threat protection
- D) Asset review and administration
How security of outsourced services can be evaluated?
- A) Spot security checks
- B) Ask for 3rd party security review
- C) Include outsourced scope in internal audit
- D) Vulnerability assessment and penetration testing
In an enterprise which software should be allowed to install and execute?
- A) Softwares displayed on notice board.
- B) Softwares included in white-list.
- C) Any freely available software.
- D) Only paid software.
What practice of VM scanning mostly organizations follow in our local market?
- A) Monthly scan and remediate
- B) Fortnightly scan and remediate
- C) Once a year or not at all
- D) Quarterly scan and remediate
Which screen is displayed immediately after login screen in NESSUS scanner?
- A) Scan screen
- B) Vulnerability management screen
- C) Policy compliance screen
- D) Dashboard
Which one of the following is considered the first step in a vulnerability scan?
- A) Port scanning
- B) Firewall detection
- C) TCP/UDP service delivery
- D) Checking if the remote host is alive
In an enterprise which softwares should be allowed to install and execute?
- A) Any freely available software
- B) Softwares displayed on notice board
- C) Only paid software
- D) Softwares included in whitelist
Which of the following policies NESSUS can scan for compliance?
- A) CIS benchmarks
- B) SEI guidelines
- C) NIST controls
- D) OWAPS top 10
Which of the following function is performed by IT operation team in vulnerability management process?
- A) Takes backup and downtime
- B) Run vulnerability scanner
- C) Share report with management
- D) Tracks remediation timeline
What feature set QUALYS scanner offers?
- A) Not scalable
- B) Cloud based service
- C) Quarterly subscription
- D) Cost effective
Which of the following statement is correct?
- A) NVD is superset of CVSS
- B) CVE is superset of NVD
- C) NVD is superset of CVE
- D) NVD is an open standard for assigning vulnerability impacts
Which of the following scan is deeper and gives more detailed scanning results?
- A) Un-credentialed vulnerability discovery
- B) Credentialed vulnerability scanning
- C) Initial options profile scan
- D) Asset discovery scan
What should standard secure configuration images represent?
- A) Hardened versions of OS only.
- B) Hardened versions of underlying OS and application installed on system.
- C) Hardened versions of application installed on system only.
- D) Default configuration version of OS only.
Against which frameworks nessus scanner gives configuration auditing feature?
- A) CIS and DISA
- B) SCAP AND SOX
- C) CYBERSCOPE AND GLBA
- D) HIPAA AND HITECH
Which of the following tools are offered free by QUALYS?
- A) PCI compliance
- B) Web application firewall
- C) Browser check
- D) Web application scanner
Against which frameworks NESSUS scanner gives configuration auditing feature?
- A) CYBERSCOPE AND GLBA
- B) CIS and DISA
- C) HIPAA AND HITECH
- D) FFIEC AND FISMA
Which types of plugins are supported by NESSUS scanner?
- A) CIS and DISA
- B) SEI
- C) Sans and NIST
- D) OWASP
Which activities are carried out at stage 1 of transformation model?
- A) Establish a MSB
- B) Apply CIS/DISA benchmarks
- C) Take stock of the assets and prioritize
- D) All of the given