Vulnerability Management & Assessment Flashcards
CompTIA CySA+ CS0-004 (V4) Flashcards

| Front | Back |
| Authenticated scan definition and main advantage | Scanner logs in to target to run checks which yields higher accuracy and fewer false positives due to visibility into system state |
| Best practice for scan frequency by asset type | High risk assets weekly medium risk monthly low risk quarterly |
| Common causes of scan coverage gaps | Unauthenticated credentials missing network segments excluded and misconfigured scanners |
| Common patch management lifecycle stages | Assess approve test deploy monitor |
| Define asset criticality | Classification of asset importance based on business impact confidentiality requirements and recovery needs |
| Define false positive rate metric | Percentage of reported vulnerabilities that are determined not to be real after validation |
| Define Mean Time To Remediate MTTR | Average time from vulnerability discovery to verified remediation or closure |
| Difference between patch assessment and patch deployment | Assessment identifies needed patches Deployment installs patches to systems |
| Evidence examples to confirm a vulnerability | Proof of exploit screenshots logs process or file changes and presence of vulnerable software versions |
| Example prioritization model combining CVSS and asset criticality | Weighted score equals CVSS Base times asset criticality multiplier plus exploitability bonus |
| Example SLA for critical severity remediation | Remediate critical vulnerabilities within 7 calendar days or mitigate with compensating control and document exception |
| First three steps in a remediation workflow | Identify and prioritize create ticket assign owner |
| How to calculate remediation rate | Number of vulnerabilities remediated over a period divided by number detected in that period |
| How to document exceptions and compensating controls | Record exception owner rationale compensating control description and review expiry date in ticketing system |
| How to integrate vulnerability management with ticketing systems | Automate ticket creation enrich tickets with vulnerability context and track remediation progress |
| How vulnerability findings should be reported to executives | Summarize key trends risk posture remediation rate and top business critical unresolved items |
| Integration points between VM and SIEM | Feed vulnerability context to SIEM for prioritized alerting and use SIEM detections to validate exploit attempts |
| Interpreting CVSS score ranges and severity | 0 0 to 3.9 Low 4.0 to 6.9 Medium 7.0 to 8.9 High 9.0 to 10.0 Critical |
| Key factors for asset prioritization | Business criticality exposure exploitability and existing compensating controls |
| List CVSS base metric abbreviations and what they represent | AV AC PR UI S C I A where AV is Attack Vector AC Attack Complexity PR Privileges Required UI User Interaction S Scope C Confidentiality I Integrity A Availability |
| Purpose of CVSS temporal and environmental scores | Temporal adjusts Base for exploit code maturity and remediation level Environmental tailors score to asset specific impact and controls |
| Role of threat intelligence in vulnerability management | Provides exploit maturity and active exploitation data to elevate prioritization and guide rapid remediation |
| Simple risk formula used in prioritization | Risk equals Likelihood multiplied by Impact |
| Three strategies to reduce false positives | Use authenticated scans tune detection rules and validate with actual proof or proof of concept |
| Two main cons of authenticated scanning | Risk of account misuse and potential impact on target stability during scanning |
| Two main pros of authenticated scanning | Higher fidelity detection and ability to identify missing patches and configuration issues |
| Unauthenticated scan definition and main use | Scanner probes services from network without credentials useful for external attack surface assessment and blind testing |
| Vulnerability triage checklist items | Verify detection check for proof determine business impact assign severity and create remediation ticket |
| What is a false positive in vulnerability scanning | Finding reported as a vulnerability that upon validation is not a real security issue |
| What is vulnerability aging | Time duration a vulnerability remains open from first detection to closure |
| When to apply hotfix versus scheduled patch | Hotfix for critical immediate fixes scheduled patch for routine maintenance windows |
| When to choose penetration testing over scanning | Use pentest for business critical apps or when deeper exploit validation and chain attacks need to be proven |
| When to use unauthenticated scans | When assessing internet facing exposure or when credentials are unavailable or not trusted |
About the Flashcards
Flashcards for the CompTIA CySA+ exam offer a concise, practical review of core vulnerability management terminology and concepts. Use this deck to reinforce definitions, key metrics like CVSS and MTTR, common workflows, and exam-style distinctions between scanning approaches and remediation steps.
The cards cover authenticated versus unauthenticated scanning, CVSS base/temporal/environmental scoring, asset criticality and prioritization using simple risk formulas, false positive identification and validation evidence, remediation ticketing and SLA targets, patch management lifecycle and hotfix versus scheduled patch decisions, triage checklists, and integration points with ticketing systems and SIEM for reporting and tracking remediation progress.
Topics covered in this flashcard deck:
- Authenticated vs unauthenticated scans
- CVSS metrics and scoring
- Asset prioritization and risk
- False positives and validation
- Remediation workflows and SLAs
- Patch management lifecycle