Vulnerability Management CS0-003 Practice Quiz
528 exam-style questions covering 30% of the CS0-003 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA CySA+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Which description best matches Asset discovery in CySA+ Objective 2.0 Vulnerability Management?
- A. Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment.
- B. Map scans discover reachable hosts, ports, services, and network layout so analysts understand what exists in the environment.
- C. Device fingerprinting identifies device type, operating system, service versions, or platform traits based on observed characteristics.
- D. Scheduling determines when vulnerability scans run so they avoid unacceptable business disruption or missed assessment windows.
Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment. This is the correct answer.
Which option correctly defines Map scans?
- A. Regulatory requirements define scan timing, evidence, scope, controls, or reporting obligations required by laws, contracts, or standards.
- B. Map scans discover reachable hosts, ports, services, and network layout so analysts understand what exists in the environment.
- C. Internal scanning assesses assets from inside the organization’s network or trusted environment.
- D. External scanning assesses internet-facing or externally reachable assets from outside the organization’s network boundary.
Map scans discover reachable hosts, ports, services, and network layout so analysts understand what exists in the environment. This is the correct answer.
A vulnerability scan is being planned or interpreted with Asset discovery in mind. Which choice best describes the concept?
- A. Non-credentialed scanning should be selected when the scenario matches this purpose: Non-credentialed scanning checks targets without authenticated access and usually sees only externally visible services and banners.
- B. Asset discovery should be selected when the scenario matches this purpose: Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment.
- C. Passive scanning should be selected when the scenario matches this purpose: Passive scanning observes traffic or data without actively probing targets, reducing disruption risk.
- D. Active scanning should be selected when the scenario matches this purpose: Active scanning sends probes or requests to targets to identify hosts, services, versions, and vulnerabilities.
Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment. This matches the vulnerability management scenario without shifting to a related but different concept. This is the correct answer.
A vulnerability scan is being planned or interpreted with Map scans in mind. Which choice best describes the concept?
- A. Critical infrastructure should be selected when the scenario matches this purpose: Critical infrastructure includes systems essential to public safety, economic stability, utilities, transportation, healthcare, or national functions.
- B. Operational technology should be selected when the scenario matches this purpose: Operational technology monitors or controls physical processes, industrial equipment, or facility operations.
- C. Map scans should be selected when the scenario matches this purpose: Map scans discover reachable hosts, ports, services, and network layout so analysts understand what exists in the environment.
- D. Industrial control systems should be selected when the scenario matches this purpose: Industrial control systems manage industrial processes such as manufacturing, energy, water, and transportation environments.
Map scans discover reachable hosts, ports, services, and network layout so analysts understand what exists in the environment. This matches the vulnerability management scenario without shifting to a related but different concept. This is the correct answer.
A vulnerability scan is being planned or interpreted with Device fingerprinting in mind. Which choice best describes the concept?
- A. OWASP should be selected when the scenario matches this purpose: Open Web Application Security Project provides guidance, tools, and references for web application security risks and testing.
- B. ISO 27000 series should be selected when the scenario matches this purpose: The ISO 27000 series provides international standards for information security management systems and related controls.
- C. Network scanning and mapping should be selected when the scenario matches this purpose: Network scanning and mapping tools identify reachable hosts, ports, services, relationships, and network exposure.
- D. Device fingerprinting should be selected when the scenario matches this purpose: Device fingerprinting identifies device type, operating system, service versions, or platform traits based on observed characteristics.
Device fingerprinting identifies device type, operating system, service versions, or platform traits based on observed characteristics. This matches the vulnerability management scenario without shifting to a related but different concept. This is the correct answer.
A scan design must avoid disruption while still producing useful findings. Which scenario best matches Asset discovery?
- A. A scenario matches CIS benchmarks when the analyst needs this distinction: Center for Internet Security benchmarks provide secure configuration recommendations for systems, applications, and platforms.
- B. A scenario matches OWASP when the analyst needs this distinction: Open Web Application Security Project provides guidance, tools, and references for web application security risks and testing.
- C. A scenario matches Asset discovery when the analyst needs this distinction: Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment.
- D. A scenario matches ISO 27000 series when the analyst needs this distinction: The ISO 27000 series provides international standards for information security management systems and related controls.
Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment. This distinction matters because choosing a nearby concept would change the scan design, tool choice, prioritization, mitigation, or response action. This is the correct answer.
A scan design must avoid disruption while still producing useful findings. Which scenario best matches Map scans?
- A. A scenario matches Burp Suite when the analyst needs this distinction: Burp Suite is a web application testing platform used for intercepting, analyzing, and testing HTTP and HTTPS traffic.
- B. A scenario matches Zed Attack Proxy when the analyst needs this distinction: Zed Attack Proxy is an OWASP web application security scanner and proxy used for finding web vulnerabilities.
- C. A scenario matches Arachni when the analyst needs this distinction: Arachni is a web application security scanner used to assess web applications for vulnerabilities.
- D. A scenario matches Map scans when the analyst needs this distinction: Map scans discover reachable hosts, ports, services, and network layout so analysts understand what exists in the environment.
Map scans discover reachable hosts, ports, services, and network layout so analysts understand what exists in the environment. This distinction matters because choosing a nearby concept would change the scan design, tool choice, prioritization, mitigation, or response action. This is the correct answer.
A senior analyst must choose the safest scanning approach without losing needed coverage. Which answer applies Asset discovery most accurately?
- A. OpenVAS is the best answer when the vulnerability management decision depends on this exact meaning: OpenVAS is an open-source vulnerability scanning framework used to assess systems for known vulnerabilities and misconfigurations.
- B. Debuggers is the best answer when the vulnerability management decision depends on this exact meaning: Debuggers inspect program execution, memory, registers, crashes, and code behavior to analyze software flaws.
- C. Immunity debugger is the best answer when the vulnerability management decision depends on this exact meaning: Immunity debugger is a Windows debugger often used for exploit development and vulnerability analysis.
- D. Asset discovery is the best answer when the vulnerability management decision depends on this exact meaning: Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment.
Asset discovery identifies systems, services, devices, cloud resources, applications, and other assets that may need vulnerability assessment. This applies the concept at the decision point where the wrong term would lead to an incorrect remediation, risk, or vulnerability-handling decision. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-cysa-plus/vulnerability-management/
<a href="https://quizbuffet.com/comptia-cysa-plus/vulnerability-management/">CompTIA CySA+ Vulnerability Management practice quiz on QuizBuffet</a>
Other CS0-003 Domains
← Back to CS0-003 practice test overview
Questions are written against the published CS0-003 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.