CVE Assessment & Patch Management Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CVE Assessment & Patch Management flashcards as text
Which CVSS v3.1 metric describes whether an attacker needs to be on the same network segment as the vulnerable component?
Answer: Attack Vector: Adjacent
The 'Adjacent' value for Attack Vector means the attacker must be on the same physical or logical network as the target, such as Bluetooth or a local subnet.
A patch released outside of the normal patch cycle to address a critical zero-day vulnerability is called a:
Answer: Hotfix or out-of-band patch
An out-of-band or hotfix patch is released urgently outside the scheduled patch cycle to address actively exploited or critical vulnerabilities.
What does the CVE identifier format CVE-2023-12345 indicate?
Answer: The vulnerability was assigned in 2023 with sequence number 12345
CVE identifiers follow the format CVE-[year]-[sequence], where the year reflects when the CVE ID was assigned, not when the vulnerability was discovered or patched.
In patch management, what is a 'patch window'?
Answer: A scheduled maintenance period when patches are applied to minimize disruption
A patch window is a predetermined maintenance window during which IT teams apply patches to minimize impact on business operations.
Which organization is the primary CVE Numbering Authority (CNA) responsible for assigning CVE IDs to vulnerabilities in Microsoft products?
Answer: Microsoft Corporation
Microsoft is a CVE Numbering Authority (CNA) and assigns CVE IDs for vulnerabilities discovered in its own products, while MITRE oversees the overall CVE program.
When evaluating a CVE, the 'Scope' metric in CVSS v3.1 set to 'Changed' means:
Answer: The vulnerability impacts components beyond the vulnerable component's authorization scope
A 'Changed' Scope indicates that exploitation can affect components with different authorization scope, such as a VM escape affecting the hypervisor.
Which patch management metric measures the average time from patch availability to deployment across all systems?
Answer: Mean Time to Patch (MTTP)
Mean Time to Patch (MTTP) measures the average elapsed time from when a patch becomes available to when it is deployed across target systems.