AI-Assisted Vulnerability Management
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is the safest role for AI in vulnerability management?
A. Automatically closing every finding without review.
B. Assisting with evidence organization, summarization, deduplication, prioritization support, and remediation drafting.
C. Replacing asset owners and security teams entirely.
D. Running unauthorized testing against unknown systems.
2. Why does asset context matter when prioritizing vulnerabilities?
A. Asset criticality, exposure, data sensitivity, ownership, and business function affect real-world risk.
B. Scanner severity is always enough by itself.
C. Asset context only matters after remediation.
D. Ownership should be ignored.
3. Which evidence source can support vulnerability management?
A. Unsupported guesses.
B. Unverified rumors.
C. Scanner findings, configuration assessments, dependency scans, cloud posture findings, tickets, and validation records.
D. Decorative screenshots with no system context.
4. Why should AI-assisted deduplication preserve source evidence?
A. Source evidence is not useful after grouping.
B. Deduplication should hide unresolved risk.
C. Evidence should be deleted after summarization.
D. Reviewers need to trace grouped findings back to original records and affected assets.
5. What is a false positive?
A. A reported finding that does not apply as described after validation.
B. A confirmed high-risk weakness.
C. A remediation ticket with an owner.
D. A recurring vulnerability trend.
6. What should risk-based prioritization combine?
A. Only the order findings appear in a scan report.
B. Only the vulnerability title.
C. Technical severity, exploitability, exposure, asset value, data sensitivity, compensating controls, and business impact.
D. Only the easiest tickets to close.
7. Why should AI not silently decide remediation priorities?
A. AI cannot summarize findings.
B. Priorities require human accountability, business context, validation, and risk judgment.
C. Prioritization is never needed.
D. Scanner data is always complete.
8. Which item is an example of remediation?
A. Ignoring a confirmed weakness indefinitely.
B. Deleting all scan results.
C. Renaming the vulnerability.
D. Patching, upgrading, changing configuration, removing a vulnerable component, or restricting exposure.
9. What makes a remediation ticket useful?
A. Clear affected assets, evidence, risk explanation, required action, owner, priority, and validation expectations.
B. A vague title with no context.
C. No owner or due date.
D. Unsupported AI conclusions.
10. Why is validation required before closing a vulnerability?
A. It makes future scanning unnecessary.
B. It helps confirm the weakness was corrected, mitigated, accepted, or otherwise dispositioned with evidence.
C. It replaces asset inventory.
D. It proves the system has no remaining risk.
11. What is a compensating control?
A. A reason to ignore every finding.
B. A replacement for all vulnerability management.
C. A control or measure that reduces risk when primary remediation is delayed or not immediately feasible.
D. A dashboard color setting.
12. Why should vulnerability reports include uncertainty when appropriate?
A. Uncertainty makes reports useless.
B. Reports should always sound certain even without evidence.
C. Uncertainty should be hidden from decision-makers.
D. Some findings depend on incomplete evidence, assumptions, validation status, or changing threat context.
13. Which metric can help show vulnerability management health?
A. Aging of unresolved high-risk findings.
B. The number of icons in the report.
C. The color of the dashboard.
D. The length of ticket titles only.
14. Why is vulnerability data sensitive?
A. It has no security value.
B. It may reveal weaknesses, asset names, internal architecture, exposure, ownership, or remediation gaps.
C. It should always be public.
D. It cannot affect risk.
15. What is source provenance in AI-assisted vulnerability management?
A. A password reset method.
B. A cloud billing tag only.
C. A record of where a finding, claim, summary, or recommendation came from.
D. A user interface theme.
16. Which statement best summarizes AI-assisted vulnerability management?
A. AI should replace scanners, engineers, and risk owners.
B. AI output is always evidence by itself.
C. AI should be used to perform unauthorized vulnerability discovery.
D. AI can help organize, summarize, prioritize, and communicate vulnerability work, but humans must validate evidence, own risk decisions, and confirm remediation.
Submit Quiz
Previous