Vulnerability Management Detection and Response (VMDR) Exam 2.0
February 28, 2023 | Author: Anonymous | Category: N/A
Short Description
Download Vulnerability Management Detection and Response (VMDR) Exam 2.0...
Description
1. Which type type of Dashboard Dashboard Widget Widget can be congur congured ed to change change color, color, as its tracked tracked data reaches reaches specic condions or threshold levels? Bar Chart
Table
Count
Pie Chart
2. Which of the the following following frequencie frequencies, s, can be used used to schedule schedule a Patch Patch Deploymen Deploymentt Job? Select Select all that apply. Weekly
Quarterly
Annually
Daily
3. Which Qualys Qualys applica applicaon on module module is NOT NOT include include in the Default Default VMDR Ac Acva vaon on Key? Patch Management
PCI Compliance
Cybersecurity Asset Management
Vulnerability Management
4. Which Qualys Qualys applica applicaon, on, provides provides the the Real-Time Real-Time Threat Threat Indicator Indicatorss (RTIs) used used in the VM VMDR DR Priorizaon Report? Patch Management
Asset Inventory
Threat Protecon
Vulnerability Management
5. The Qualys Qualys CSAM applic applicaon aon disngui disnguishes shes your your asset invent inventory ory using using which of of the following following categories? Select all that apply. Soware
Hardware
Firmware
Operang System
6. Which “Acve “Acve Threat” Threat” category category iinclude ncludess aacks aacks that require require lile lile skill and and do not req require uire addional informaon? Predicted High Risk
Easy Exploit
Public Exploit
Zero Day
7. Presently, Presently, you can can add up up to _____ _____ patche patchess to a single job. 2000
1250
1750
1500
8. Which Qualys Qualys technolo technology gy provides provides a patch patch download download cache, cache, to achieve achieve a more more ecient ecient distribuon of downloaded patches, to local agent host assets? Qualys Passive Sensor
Qualys Scanner Appliance
Qualys Gateway Server
Qualys Connector
9. Using the the “Search” “Search” eld (found (found in the VULNER VULNERABILIT ABILITIES IES sec secon on of VMDR), which which query query will produce a list of “patchable” vulnerabilies? vulnerabilies.vulnerability.qualysPatchable:TRUE vulnerabilies.vulnerability.isPatchable:TRUE
vulnerabilies.vulnerability.qualysPatchable:FALSE vulnerabilies.vulnerability.isPatchable:FALSE 10. Which of the following queries will dis display play assets with with a Relaonal Database Database Management System? soware:(category1:Databases / RDBMS) soware:(Databases / RDBMS), soware: (category2:Databases / RDBMS) soware:(category:Databases / RDBMS) 11. By default, which of of the following factors are used by the VMDR Priorizaon Priorizaon Report, to priorize vulnerabilies? Select all that apply. Vulnerability age
Real me Threat Indicators
Compliance Posture
Aack Surface
12. Which “Acve Threat” category includes vulnerabilies th that at are acvely aacked and have have no patch available? Easy Exploit
Malware
Exploit Kit
Zero Day
13. Which of the following convenons can be be used to include or ass assign ign host assets to a job? job? Select all that apply. Business Unit
Asset Name
Asset Tag
Asset Group
14. Qualys categorizes your your soware inventory inventory by which of of the following license types? Select all that apply. Premier
Trial
Commercial
Open Source
15. You are in the process of of inducng new employees employees on the Global AssetView AssetView applicaon. In your presentaon you have to add the features of this applicaon. Which features from the below menoned list will you include? Select all that apply. Categorized and normalized hardware and soware informaon Ability to dene and track unauthorized soware Asset Cricality Score Discovery and inventory of all IT assets 16. You have been asked asked to create a “Zero-Touch” “Zero-Touch” patch deployment job. You You have already scheduled this job to run once a week. What addional requirement must be met? Select patches using Asset Tags
Defer patch selecon to a later me
Automate patch selecon using QQL
Select patches manually
17. Once you establish your priority opon you can generate generate your Priorizaon Priorizaon Report. By default this report will produce a list of _________ that match your priority opons. Patches
Threat Feeds
Vulnerabilies
Assets
18. Once you establish your priority opon you can generate generate your Priorizaon Priorizaon Report. By default this report will produce a list of _________ that match your priority opons. Create Dashboard widgets for all the contents of the report Export the report to dashboard and create a dynamic widget Schedule a report to run on a regular basis Run a report every me it is needed 19. Aer Qualys Cloud Agent has been been successfully installed on a target host, which of the followi following ng “Patch Management” setup steps must be completed, before host patch assessments can begin? Select all that apply. Assign host to CA Conguraon Prole (with PM enabled) Acvate PM module on host Assign host to a PM Job Assign host to an enabled PM Assessment Prole 20. You have to priorize the vulnerabilies by age b before efore you go ahead and generate generate a Priorizaon Report. When you are priorizing vulnerabilies by age, you have the opons of: Select all that apply. Vulnerability Age
Detecon Age
Priority Age
Installaon Age
21. In CSAM, the term “unidene “unidened” d” means: Select all that apply. There isn’t enough informaon gathered to determine the OS/hardware/soware Qualys couldn’t fully ngerprint the OS There is enough informaon, but the data isn’t catalogued in CSAM yet Qualys could fully ngerprint the OS but it’s not in your subscripon 22. You were unable to search search some of your Operang Operang Systems using a lifecycle query. query. Later, you found out the reason. The lifecycle stage of the operang system you were searching was: End of life
End of support
Obsolete
General Availability
23. Which of the following condions must be met, in order for Qualys Patch Management to successfully patch a discovered vulnerability? Select all that apply. The vulnerability should be less than 30 days The vulnerability must be conrmed, The vulnerability’s host must be running Qualys Cloud Agent The vulnerability must be patchable
24. You have to run a patch job job on a regular basis. Which of the following following will you follow in order to make your work ecient? Select all that apply. Use Asset Tags as targets for patch deployment jobs Use the dashboard to monitor Schedule patch job on a monthly basis Once test deployments are veried Clone the deployment job and include producon asset tags 25. The Threat Feed leverages leverages data from mulple sources. sources. Which of the following sources are used? Select all that apply. Other Sources Exploit Sources Malware Sources Qualys Threat and Malware Research Team 26. You have deployed several several thousand Qualys C Cloud loud Agents, and now you would would like to conserve network bandwidth by allowing your agents to store and share their downloaded patches (from a central locaon). Which Qualys technology is the best t to solve this challenge? Qualys Passive Sensor Qualys Gateway Server Qualys Cloud Connector Qualys Scanner Appliance 27. You have to analyse the the threat intelligence informaon informaon provided by Qualys Thre Threat at and Malware Labs. Where will you nd this informaon? VMDR > Vulnerabilies tab > Asset
VMDR > Dashboard tab
VMDR > Priorizaon tab > Threat Feed
VMDR > Priorizaon tab > Reports
28. Your colleague has just completed completed the following steps to setup setup your Qualys account for patching: 1. Installed Qualys Cloud Agent on target hosts. 2. Assigned all Agent hosts to a Conguraon Prole with PM conguraon enabled. 3. Acvated the PM applicaon module for all Agent hosts. 4. Assigned all hosts to an enabled Assessment Prole. Although Deployment Jobs have been created and enabled, patches are not geng installed. What step did your colleague miss? Targeted assets must be congured to consume a patching license Targeted assets must be labelled with the ""Patchable"" Asset Tag Targeted assets must be added to the ""Patch Management"" Asset Group Targeted assets must be added to the Patch Catalogue 29. A pre-deployment message message appears at the start start of a patch job. You have tto o create a deployment job for a Windows user wherein wherein he will receive a no nocaon caon message to the user indicang that a reboot is required. What communicaon opon will you select? Reboot message
Reboot Countdown
Supress Reboot
Reboot Request
30. Your IT team has congured congured a patch window to run a deployment deployment job within 5 hours. Due to some reason you were not able to start the patch installaon within that window. What status will they host display? Not aempted
Timed out
Retry
Failed
View more...
Comments