D340 Cyber Defense and Countermeasures - Set 1 - Part 2

Test your knowledge of technical writing concepts with these practice questions. Each question includes detailed explanations to help you understand the correct answers.

Question 21: Which action most effectively reduces attack surface?

Question 22: What is an attack vector?

Question 23: What is a vulnerability?

Question 24: How do vulnerability, threat, and risk relate?

Question 25: What is CVSS used for?

Question 26: Why should CVSS score alone not determine patching priority?

Question 27: What is a CVE identifier?

Question 28: What is an exploit?

Question 29: What is a proof-of-concept exploit?

Question 30: Why does public exploit availability increase urgency to patch?

Question 31: What is a security control?

Question 32: What is an administrative (managerial) control?

Question 33: What is a technical (logical) control?

Question 34: What is a compensating control?

Question 35: What is a deterrent control?

Question 36: What is a corrective control?

Question 37: What is the purpose of a security framework such as the NIST Cybersecurity Framework?

Question 38: What are the five core functions of the NIST Cybersecurity Framework?

Question 39: Why is the Identify function foundational to the others?

Question 40: What is asset inventory's role in cyber defense?


Complete the Captcha to view next question set.


Quick View

Don't Want to Study?

Save Time on Studies, Spend More with Family & Friends! Pay-After-you-Pass!

Get Exam Support