D340 Cyber Defense and Countermeasures - Set 1 - Part 2
Test your knowledge of technical writing concepts with these practice questions. Each question includes detailed explanations to help you understand the correct answers.
Question 21: Which action most effectively reduces attack surface?
Question 22: What is an attack vector?
Question 23: What is a vulnerability?
Question 24: How do vulnerability, threat, and risk relate?
Question 25: What is CVSS used for?
Question 26: Why should CVSS score alone not determine patching priority?
Question 27: What is a CVE identifier?
Question 28: What is an exploit?
Question 29: What is a proof-of-concept exploit?
Question 30: Why does public exploit availability increase urgency to patch?
Question 31: What is a security control?
Question 32: What is an administrative (managerial) control?
Question 33: What is a technical (logical) control?
Question 34: What is a compensating control?
Question 35: What is a deterrent control?
Question 36: What is a corrective control?
Question 37: What is the purpose of a security framework such as the NIST Cybersecurity Framework?
Question 38: What are the five core functions of the NIST Cybersecurity Framework?
Question 39: Why is the Identify function foundational to the others?
Question 40: What is asset inventory's role in cyber defense?
Don't Want to Study?
Save Time on Studies, Spend More with Family & Friends! Pay-After-you-Pass!
Get Exam Support