Risk Analysis and Prioritization Quiz

5 questions Pass: 70% +25 pts

Quiz covering Threat and Vulnerability Management

Risk Analysis and Prioritization Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which of the following best describes the purpose of a vulnerability scan in a network environment?

  2. 2

    When performing qualitative risk analysis, which two factors are most commonly used to calculate the risk level?

  3. 3

    An organization has identified a critical vulnerability on a legacy server that cannot be patched due to compatibility issues. Which of the following is the most appropriate risk management strategy?

  4. 4

    You are prioritizing vulnerabilities using the CVSS framework. Which metric group represents the characteristics of a vulnerability that do not change over time or across environments?

  5. 5

    A security analyst is reviewing a vulnerability report and notes a 'Critical' vulnerability on an internal system that has no network connectivity to the internet. How should the analyst prioritize this relative to a 'High' vulnerability on an internet-facing web server?