MCQ Bank
Which of the following scan is deeper and gives more detailed scanning results?
- A) Un-credentialed vulnerability discovery
- B) Credentialed vulnerability scanning
- C) Initial options profile scan
- D) Asset discovery scan
What should standard secure configuration images represent?
- A) Hardened versions of OS only.
- B) Hardened versions of underlying OS and application installed on system.
- C) Hardened versions of application installed on system only.
- D) Default configuration version of OS only.
Against which frameworks nessus scanner gives configuration auditing feature?
- A) CIS and DISA
- B) SCAP AND SOX
- C) CYBERSCOPE AND GLBA
- D) HIPAA AND HITECH
Which of the following tools are offered free by QUALYS?
- A) PCI compliance
- B) Web application firewall
- C) Browser check
- D) Web application scanner
Against which frameworks NESSUS scanner gives configuration auditing feature?
- A) CYBERSCOPE AND GLBA
- B) CIS and DISA
- C) HIPAA AND HITECH
- D) FFIEC AND FISMA
Which types of plugins are supported by NESSUS scanner?
- A) CIS and DISA
- B) SEI
- C) Sans and NIST
- D) OWASP
Which activities are carried out at stage 1 of transformation model?
- A) Establish a MSB
- B) Apply CIS/DISA benchmarks
- C) Take stock of the assets and prioritize
- D) All of the given
Which of the following are common vulnerability scanners?
- A) Forcepoint & redwolf
- B) Nessus & rapid7
- C) Openvas & qualys
- D) Nessus, rapid7, Openvas & qualys
What information we get from open TCP and UDP ports?
- A) Whether host is alive or not
- B) Which OS is running on the host
- C) Network details of the host
- D) Which services are running on host
Which subscription service model QUALYS offers?
- A) Quarterly subscription
- B) Monthly subscription
- C) Bi-annual subscription
- D) Annual subscription
Which of the following are considered cumulative and product specific?
- A) Hotfixes,Service packs
- B) Qfes,Hotfixes
- C) Service packs
- D) Security patches,Service packs
How many TCP and UDP ports are scanned in a default scan?
- A) No ports are scanned by default
- B) 1900 UDP ports and 180 TCP ports
- C) 65, 535 TCP ports
- D) 1900 TCP ports and 180 UDP ports
How security of outsourced services can be evaluated?
- A) Spot security checks
- B) Ask for 3rd party security review
- C) Include outsourced scope in internal audit
- D) Vulnerability assessment and penetration testing
In an enterprise which softwares should be allowed to install and execute?
- A) Any freely available software
- B) Softwares included in whitelist
- C) Only paid software
- D) Softwares displayed on notice board
Against which frameworks NESSUS scanner gives configuration auditing feature?
- A) CYBERSCOPE AND GLBA
- B) CIS and DISA
- C) FFIEC AND FISMA
- D) HIPAA AND HITECH
Which subscription service model QUALYS offers?
- A) Annual subscription
- B) Bi-annual subscription
- C) Quarterly subscription
- D) Monthly subscription
Which team tests the patches in test environment in vulnerability management process?
- A) IT operations team
- B) Information security team
- C) Business team
- D) Risk & compliance team
What practice of VM scanning mostly organizations follow in our local market?
- A) Quarterly scan and remediate
- B) Monthly scan and remediate
- C) Fortnightly scan and remediate
- D) Once a year or not at all
Which activities are carried out at stage 1 of transformation model?
- A) Apply CIS/DISA benchmarks
- B) Take stock of the assets and prioritize
- C) All of the given
- D) Establish a MSB
Which of the following function is performed by IT operation team in vulnerability management process?
- A) Share report with management
- B) Run vulnerability scanner
- C) Takes backup and downtime
- D) Tracks remediation timeline