Vulnerability Assessment: Protecting Your Organisation

This test consist of question related the IT course "Vulnerability Assessment" for the IT network security. This test is useful for GATE/UGC/NET and academics students.

15 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Which of the following is/are applicable for Common Vulnerabilities and Exposures (CVE)?

  1. It is used to maintain the security of the database in a shared medium.
  2. It provides a baseline for the security tools related to the organisation.
  3. It is a list or dictionary that provides common names for publicly known information security vulnerabilities and exposures.
  4. The MITRE Corporation maintains CVE and manages the CVE Editorial Board.
  5. All of the above
Question 2 Multiple Choice (Single Answer)

Which of the following is/are applicable for vulnerability assessments task?

  1. Finds potential exploits before crackers find them
  2. Creates proactive focus on information security
  3. Results in systems being kept up to date and patched
  4. Promotes growth and aids in developing staff expertise
  5. All of the above
Question 3 Multiple Choice (Single Answer)

What does 'CVE OUTPUT' mean in CVE-Compatibility?

  1. It has the information that includes the related CVE name(s).
  2. It acts like the repository owner and is used to provide a mapping relative to a specific version of CVE.
  3. A user can search using a CVE name to find related information.
  4. Both (1) and (2)
  5. Both (1) and (3)
Question 4 Multiple Choice (Single Answer)

Which of the following is known as 'Vulnerability Monitor' component in vulnerability assessment?

  1. It is used to identify and store the information related to vulnerabilities in the system.
  2. It collects the information and executes the files for the database specific to the vulnerability monitor.
  3. It checks the version of a started program for vulnerabilities against a special database.
  4. The vulnerability check is performed in the background mode and does not delay the program start.
  5. Both (3) and (4)
Question 5 Multiple Choice (Single Answer)

Which of the following is/are applicable for the Security of Database using CVE?

  1. It is based on the CVE list to identify the vulnerabilities in the database.
  2. CVE has some numbers, IDs and unique identifier to detect vulnerability from the database.
  3. Security of the database is officially compatible.
  4. The CVE names, which are used as references in the CVE-ID field in all Alerts Vulnerability definitions stored in the Definitions Repository.
  5. All of the above
Question 6 Multiple Choice (Single Answer)

Which of the following is known as 'Vulnerability Scan'?

  1. It is used to identify and store the information related to vulnerabilities in the system.
  2. It collects the information and executes the files for the database specific to the vulnerability monitor.
  3. It checks the version of a started program for vulnerabilities against a special database.
  4. The vulnerability check is performed in the background mode and does not delay the program start.
  5. Both (1) and (2)
Question 7 Multiple Choice (Single Answer)

Which of the following is/are correct about preventing and detecting security vulnerabilities using VPNs in Web applications?

  1. In this approach, all the admin functionality should be remapped onto internal IPs.
  2. It allows SQL tables to be dropped, commands run on SQL servers or the Web server to have privilege escalation vulnerabilities.
  3. This approach is used to identify the common coding errors might allow shell code to be uploaded to attack the server, or malicious files uploaded for other users.
  4. Both (1) and (2)
  5. Both (1) and (3)
Question 8 Multiple Choice (Single Answer)

Which of the following is/are correct statement (s) about 'Exploit'?

  1. It is a program to attack the code of the target system.
  2. It includes the buffer flow attacks to target the arbitrary software on the malicious web server.
  3. It is a weakness or flaw in a computer application or operating system that can be exploited to cause the application to operate in a manner unintended by its designers.
  4. All of the above
  5. Both (1) and (2)
Question 9 Multiple Choice (Single Answer)

Which of the following is/are correct about 'Angry IP Scanner' tool in Port Scanners?

  1. It is used to provide port scan for the windows.
  2. This tool is one of the best unix and windows based port scanners.
  3. It is a free Windows-only closed-source TCP/UDP port scanner by Foundstone.
  4. It is a fast Windows IP scanner and port scanner.
  5. Both (1) and (4)
Question 10 Multiple Choice (Single Answer)

Which of the following is known as 'Threat'?

  1. It attacks the target organisation by spreading various malicious codes.
  2. It includes the various spyware, malware and other malicious codes.
  3. It is some flaw in our environment that a malicious attacker could use to cause damage in your organisation.
  4. It is a tool by which an attacker uses a vulnerability to cause damage to the target system.
  5. Both (1) and (2)
Question 11 Multiple Choice (Single Answer)

Which of the following is/are incorrect about active fingerprinting?

  1. It is used for transmitting the network packets to the remote hosts.
  2. It allows the scanner to obtain more accurate results than a passive scanner, and in a shorter amount of time.
  3. This approach uses the TCP/IP protocols for transmitting the packets.
  4. It is the process of analysing packets from a host on a network.
  5. None of the above
Question 12 Multiple Choice (Single Answer)

Which of the following is/are correct about passive fingerprinting in OS fingerprinting techniques?

  1. It is used for transmitting the network packets to the remote hosts.
  2. It is the process of analysing packets from a host on a network.
  3. It allows the scanner to obtain more accurate results than a active scanner, and in a shorter amount of time.
  4. These scanners are generally and inherently less accurate than active scanners due to the fact they have less control over the data they are analysing.
  5. Both (2) and (4)
Question 13 Multiple Choice (Single Answer)

Which of the following is/are correct about 'Open Vulnerability Assessment System' (OpenVAS)?

  1. It is used to provide a network security from the targeted vulnerabilities.
  2. It has a server component with a set of plugins to test various vulnerabilities in remote systems and applications.
  3. It is a multi-threaded, multi-platform web server audit tool.
  4. Both (1) and (2)
  5. All of the above
Question 14 Multiple Choice (Single Answer)

Which of the following is called 'IP fragmentation'?

  1. It provides the accessibility of the overlapping fragments within time.
  2. It determines the bugs and inconsistencies by implementing the target system.
  3. These fragments are difficult to send on some operating systems.
  4. Both (1) and (2)
  5. All of the above
Question 15 Multiple Choice (Single Answer)

What is the role of ICMP fingerprinting?

  1. It is used to discover the network path taken by a packet to reach its destination.
  2. It is used to return error messages when a datagram is not processed correctly.
  3. It is used to determine which machines are active on the network.
  4. Both (1) and (2)
  5. All of the above