CFS136 · Principles of Information Security

Chapter 12 Review: Vulnerability Management and Security Monitoring

A hands-on review station for the vulnerability management lifecycle, scanning and CVSS, SIEM and log-based monitoring, baselines, threat hunting, and indicators of compromise from Chapter 12.

Start Here

Five review stations, each a different way to practice Chapter 12. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Explain the vulnerability management lifecycle: identify, analyze, prioritize, remediate, and verify.
  • Tell apart credentialed and non-credentialed scans, and interpret scan results, including false positives and false negatives.
  • Read a CVSS (Common Vulnerability Scoring System) score, understand what its base factors measure, and know its limits.
  • Describe SIEM (Security Information and Event Management) concepts: log aggregation, normalization, correlation, and alerting.
  • Explain baselines, anomaly detection, threat hunting, and indicators of compromise, and the role of patch management.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/20Terms viewed
0/6Lifecycle phases matched
0/7Scanning answers correct
0/7Monitoring answers correct
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.