01. A customer runs Qualys and Tenable.sc against overlapping parts of its estate. The two scanners express severity on different native scales, and a solution architect proposes a custom script that converts each scanner's native severity onto a common 0 to 10 scale as findings are imported, so that vulnerabilities from both sources can be prioritized on one basis.
How should the implementer assess this proposal?
a) It is needed, because the Default Risk Rule scores each scanner's native severity directly, so two unequal scales would skew every risk score
b) It is needed, because CVSS describes a vulnerability's characteristics but takes no part in how severity is compared
c) It is unnecessary, because the Risk score comes from the scanner's own severity, with no normalization
d) It duplicates a documented function: CVSS on the vulnerability entries already normalizes severity so they are prioritized on one basis
02. An implementer adds a Risk Rule to the active risk calculator so that findings carrying known exploit information score higher. The calculator's own conditions cover the records concerned, and the new rule's conditions match them.
The rule was added at the end of the calculator's rule order, and the affected items are still being scored by the rule that was already there.
What should the implementer do?
a) Deactivate the calculator that is producing the current score so the new rule is reached
b) Narrow the calculator's conditions so that only the new rule's records reach it
c) Move the new rule above the rule that is matching first
d) Re-derive the Risk rating on the affected items
03. A remediation owner receives a vulnerable item from a Qualys import and follows it through to its vulnerability entry, which records that the fix the source published is a patch. The owner writes back that the patch will be applied at the next window and asks which identifier to put on the change request. The customer has Vulnerability Solution Management installed.
Where should the owner take the specific remediation from?
a) From the Remediation type field itself, which names the specific patch once the entry is opened in full
b) From the preferred solution, the one remediation designated among the potential solutions
c) From the NVD entry for the same CVE, whose threat-intelligence context identifies the vendor's fix
d) From the Initial Detection section of the vulnerable item
04. A customer has written three assignment rules of their own. Each names a user group for one CI class, and all three sit ahead of the base-system assignment rule that ships with the application. Routing has worked well, and an administrator now proposes deactivating the shipped rule so that only the three customer rules remain, arguing that it has not been needed since the customer rules went in.
What is the consequence for vulnerable items that none of the three customer rules matches?
a) They go to the default group instead of the support group on their CI.
b) They are routed by the first customer rule whatever its condition says, because a sequence with no rule beneath it has to end in a match.
c) Nothing changes for them, since the support group on the CI is where an item goes when no assignment rule matches it.
d) They are left with no assignment group until an analyst sets one.
05. After the first import from a new scanner integration, a CI manager finds several hundred records in the Discovered Items module. The hosts they describe are all in the CMDB: the server records were keyed in by hand from an asset register and carry a name and an owner, but no IP address, MAC address, FQDN or NetBIOS name. The scanner reports each host by IP address, FQDN and MAC address, and the CI manager asks why hosts that exist in the CMDB are being treated as unknown.
What explains the records in Discovered Items?
a) The vendor ID lookup found each CI, but a later lookup rule returned a second candidate, so the finding was parked as a discovered item
b) The property that excludes CI classes from matching parks every unmatched host in Discovered Items until it has been reviewed
c) No CI matched the findings, so an Unmatched CI was created for each host
d) The hand-keyed records are in the Reclassified state, and a record in that state is excluded from matching
06. A remediation owner moves a remediation task to Under Investigation with the Start Investigation button. The task holds thirty vulnerable items, and nobody has edited any of them individually. The next morning an analyst checks one of those items against the vendor advisory, finds that the affected package was never installed on the host, and wants to raise a false positive on that vulnerable item. The analyst has raised false positives on other records before, but on this one the request cannot be raised. No exception has been requested on the task or on the item.
What explains it?
a) The item took the task's Under Investigation state, so it is not Open.
b) Its detections are still being found by the scanner, and a false positive can be raised only once the scanner stops reporting them.
c) A false positive can be raised only on the remediation task, so the analyst must open the task record and raise it there instead.
d) The false positive approver has not yet set an Until date, which must exist before a request can be submitted on the item.
07. An instance has a single remediation target rule, which gives 14 days to every vulnerable item rated Critical. A remediation owner notices that the Critical items collected in one remediation task carry target dates spread across three weeks, and proposes that the implementer change the rule's Target (days) value until all of those items fall on the same date, so that the task can be planned around one day.
What should the implementer tell the owner?
a) Lowering Target (days) to 1 will do it, since the smaller the value added, the closer the resulting dates sit to the rule's own date.
b) No value will do it, because the days are added to each item's own Target from (date).
c) Raising Target (days) will do it once the window is wide enough, because the most restrictive rule then applies one date across all the items it matches.
d) Setting Target (days) to the length of the task's change window will do it, because the target date is measured from the day the rule was last saved.
08. A false positive request on a vulnerable item is approved, and the approver leaves the Until field on that approval empty. The item closes with the false positive substate. Reviewing the register the following month, a remediation owner asks how long the dismissal will hold before the item comes back into the remediation queue.
What is the documented answer?
a) It expires after the approval rule's set period.
b) It holds until the next scan reports the detection again, which puts the item back in the queue.
c) It is permanent, as the approver set no Until date.
d) It holds until the approving record is closed, when the item returns to Open with its previous state restored.
09. A remediation task groups six vulnerable items across two application servers. One of the servers has now been retired in the CMDB; the other stays in service, and its two items have a tested patch waiting. The instance was upgraded to Vulnerability Response v23.0 last year. The remediation owner drafts a four-step runbook for finishing the task and asks an implementer to review it before the team uses it.
Which two steps should be struck from the runbook, because the platform already produces the outcome or no longer offers the action?
(Choose two.)
a) Select Resolve on the task once the patch on the surviving server has been deployed there and verified by the CI owner
b) Close the four items on the retired server by hand, noting on each record that the host is gone
c) Request a rescan of the surviving server so the scanner can close its remaining detections
d) Select Close on the task after the last item is fixed, so that it does not linger once the work has ended
10. Working through the Discovered Items module, an analyst reclassifies an unmatched host as a Linux server. A day later the platform team confirms that it is a network appliance, and the analyst opens the record again to move it to the right class.
What is true of that record now?
a) It cannot be reclassified again through the UI
b) It can be reclassified again, because its State reverts once the class update has been saved
c) It can be reclassified again by the analyst, provided the new class is a child of the one chosen first
d) It can be reclassified again by a user holding the role that manages reclassification of unmatched items