CVE Assessment & Patch Management Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 CVE Assessment & Patch Management flashcards as text
A security team discovers that a vendor patch breaks a critical business application. What is the BEST immediate course of action?
Answer: Apply compensating controls and document a risk acceptance while working with the vendor on a fix
When a patch causes incompatibility, applying compensating controls (e.g., WAF rules, network segmentation) and formally accepting residual risk is the recommended risk management approach.
Which NVD data field provides a standardized list of weakness types associated with a CVE, helping analysts understand root causes?
Answer: CWE (Common Weakness Enumeration)
CWE entries linked to a CVE describe the underlying software weakness category (e.g., CWE-79 for XSS), aiding root-cause analysis and remediation prioritization.
In CVSS v3.1, a vulnerability with Integrity Impact: High means that:
Answer: There is total loss of integrity; the attacker can modify any or all files protected by the vulnerable component
Integrity Impact: High in CVSS v3.1 means the attacker can completely modify protected data or system files, resulting in total loss of integrity.
What is the purpose of a 'patch staging environment' in the patch management process?
Answer: To test patches on representative systems before production deployment to catch regressions
A staging environment mirrors production and is used to validate patches for compatibility and stability before they are pushed to live systems.
Which CVSS v3.1 Temporal metric lowers the effective severity when an official vendor fix is available?
Answer: Remediation Level (RL)
The Remediation Level (RL) temporal metric adjusts the score downward when an official fix exists, distinguishing between unpatched, workaround, and fully remediated states.
Which approach prioritizes patching assets based on their exposure to the internet and business criticality?
Answer: Risk-based patch prioritization
Risk-based patch prioritization factors in asset exposure, exploitability (e.g., EPSS score), and business criticality rather than relying solely on vendor severity ratings.
What does EPSS (Exploit Prediction Scoring System) provide that CVSS does not?
Answer: A probability estimate that a CVE will be exploited in the wild within the next 30 days
EPSS produces a daily probability score (0–1) predicting likelihood of exploitation in the wild, complementing CVSS severity with real-world threat intelligence.