Skip to content
ScopefileGet the app

Module 5Domain 3 of 9System Hacking Phases and Attack Techniques

Vulnerability analysis: find, score, prioritize

Vulnerability analysis is the step between finding services and acting on them: identifying weaknesses, scoring how serious each is, and deciding what to fix first. Module 5 covers the assessment types, the scoring systems, and the life cycle that strings them together.

Exam
312-50
Domain
3 of 9
Domain weight
15%
This file
~5%
Targets
15

Between enumeration and exploitation

Vulnerability analysis opens the System Hacking Phases and Attack Techniques domain, 15% of the exam (as of Oct 11, 2026) under EC-Council's blueprint v5.0. It is the analytical module of that domain: it follows enumeration, which told you what is running, and feeds system hacking, which acts on what you found.

The blueprint lists assessment concepts, classification and assessment types, tools, and reports. The high-yield material is the vocabulary of assessment types, what a score means, and the order of the management life cycle. Keep the discipline separate from a penetration test, a distinction with its own page, vulnerability assessment versus penetration test.

The vulnerability-management life cycle, step by step

  1. Pre-assessment

    Identify the assets in scope with their owners and criticality, and record a baseline. Gaps here become blind spots later.
  2. Vulnerability assessment

    Scan and analyze the in-scope systems for weaknesses. A credentialed scan logs in and reads patch levels and local configuration; an unauthenticated scan sees only what services expose from outside.
  3. Risk assessment

    Rank the findings by severity together with context.
  4. Remediation

    Patch where you can; apply compensating controls where you cannot.
  5. Verification

    Re-check that the fix held and did not open something else.
  6. Monitoring

    Keep watching, because new weaknesses appear and the inventory keeps changing. The cycle then repeats, and the report documents each pass.

Assessment types and scoring systems

The named concepts Module 5 asks you to recognize.
ConceptWhat it meansThe distinction
Internal vs external assessmentRun from inside the network vs from the internetWhich attacker position it reproduces
Credentialed vs non-credentialedA logged-in, host-level view vs the outsider's service-only viewDepth of what each one can see
CVEA public identifier for a disclosed vulnerabilityAn identifier, paired with a separate severity score
CVSSA severity score for a vulnerability; v3.1 and v4.0 are both in useHow serious the flaw is in the abstract
NVDA database that enriches CVE entries with scores and metadataWhere a scored CVE record lives

Score it and sort it

Items on assessment types, scoring and the life cycle. Settle on an answer, then read why the key holds and the distractors fail.

Answered 0/15Hits 0

T-01

When including CVSS base scores in a final penetration test report, which combination of elements BEST prevents stakeholder misinterpretation of the organizational risk?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAn exploit-prediction probability and remediation timelines add urgency data, but without the vector string or local context readers still cannot see why the score fits their environment.
  2. BReporting an already modified number with a few sub-metrics hides how the score was built, so stakeholders cannot trace or challenge the adjustment that produced it.
  3. CGeneric scanner plugin text restates the finding but never explains how this flaw's severity changes on this particular asset, so the base number is still easy to misread.
  4. DCorrect: the vector string shows which metrics produced the number in CVSS v3.1 or v4.0, and a short environmental note ties that abstract score to this organization's real exposure.
T-02

A vulnerability has a CVSSv3 vector of AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. If the attack vector changes from Adjacent (AV:A) to Network (AV:N), how does this shift the severity?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAttack vector is a base metric, and moving to Network raises the score from 8.8 to 9.8, which crosses into a different severity band.
  2. BPrivileges Required is a separate metric and stays at None; changing the attack vector does not affect it.
  3. CAttack Complexity is independent of attack vector and is already Low in this vector string.
  4. DCorrect: under CVSS v3.1 this vector scores 8.8 (High) with Adjacent, and 9.8 (Critical) once the vector becomes Network.
T-03

While conducting a web application security test, you perform actions that allow you to observe web traffic without directly interacting with the server. What type of security testing is this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: passive assessment observes traffic and behavior without sending probes to the target, lowering the risk of disruption and detection.
  2. BInternal assessment describes testing from inside the network perimeter, not whether you interact with the server.
  3. CActive assessment sends probes or requests directly to the target, which contradicts the scenario.
  4. DExternal assessment describes testing from outside the perimeter, a viewpoint rather than an observation-only method.
T-04

You have been tasked with identifying vulnerabilities in an application server and need to download appropriate tools for vulnerability assessment. Which of the following tools would you download to begin this process?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGIMP is an image editor and has no role in vulnerability assessment.
  2. BAudacity is an audio editor and is unrelated to security testing.
  3. CDropbox is a file storage and sync service, not a security assessment tool.
  4. DCorrect: Nessus is a widely used vulnerability scanner that checks hosts and applications for known flaws and misconfigurations.
T-05

Which of the following is NOT typically involved in the pre-assessment phase of vulnerability management?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: remediation fixes discovered vulnerabilities and comes after the assessment, not in the pre-assessment phase.
  2. BIdentifying assets is a core pre-assessment step, because you cannot assess systems you do not know exist.
  3. CDefining scope sets which systems, methods and time windows are authorized before any scanning begins.
  4. DThreat modeling helps prioritize what to assess and is part of preparing before the assessment phase.
T-06

Which type of vulnerability assessment starts by identifying and cataloging the services running on a network device, then utilizes this information to determine and execute relevant security tests?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABehavioral-based assessment refers to monitoring activity for anomalies, not inventorying services and then choosing tests.
  2. BPattern-based approaches match known patterns or signatures and do not start by cataloging services to infer tests.
  3. CSignature-based checks compare against known signatures without the service-inventory step described here.
  4. DCorrect: inference-based assessment first discovers services and protocols on a device, then selects and runs only the tests relevant to them.
T-07

A vulnerability scanner generates thousands of false positives regarding Apache server misconfigurations on a network consisting entirely of Nginx servers. What is the MOST appropriate tuning mechanism to resolve this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASuppressing every web-server check globally would hide genuine Nginx findings along with the noise.
  2. BAn intrusion-prevention block addresses live traffic, not false positives in a vulnerability scanner's reporting.
  3. CSwitching to passive sniffing sacrifices the active assessment rather than tuning out the specific false positives.
  4. DCorrect: selectively suppressing the irrelevant Apache signatures and scoping the scan to the actual Nginx hosts removes the noise while preserving real coverage.
T-08

Which of the following is a data repository maintained by the MITRE Corporation that houses information on publicly disclosed cybersecurity vulnerabilities?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe National Vulnerability Database is run by NIST and enriches CVE entries with scores and data; MITRE does not maintain it.
  2. BCVSS is a scoring framework, now maintained by FIRST, that rates severity rather than storing vulnerability records.
  3. CIVA is not a recognized public vulnerability repository maintained by MITRE.
  4. DCorrect: MITRE operates the CVE program, which assigns unique identifiers to publicly disclosed vulnerabilities.
T-09

Which of the following is NOT necessary to include in a vulnerability assessment report?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: the analyst's personal background adds nothing to a vulnerability report, which should focus on findings, risk and remediation.
  2. BMitigation recommendations tell owners how to reduce risk and are essential to an actionable report.
  3. CVulnerability details, such as affected systems, severity and evidence, are the core content of the report.
  4. DA methodology summary explains scope and tools, helping readers judge coverage and limitations.
T-10

What strategy ensures that all network devices are safeguarded against known vulnerabilities by applying the latest security updates?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEncryption protects data confidentiality but does not fix software flaws in devices.
  2. BCorrect: patching applies vendor security updates that close known vulnerabilities, the core of vulnerability remediation.
  3. CScanning finds vulnerabilities but does not fix them on its own.
  4. DUpgrading moves to a newer version and can remove flaws, but applying the latest security updates is specifically called patching.
T-11

A vulnerability was initially published with a high CVSS Base Score but no known exploit. Two weeks later, a functional exploit script is released publicly. How does this development affect the vulnerability metrics?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: exploit code maturity is a v3.1 temporal (Threat in v4.0) metric, so releasing a working exploit raises the temporal score to reflect the heightened real-world risk.
  2. BThe impact subscore measures confidentiality, integrity, and availability effect, which a new exploit does not change.
  3. CBase metrics capture intrinsic, fixed characteristics and are not revised when exploit code appears.
  4. DEnvironmental metrics track the asset's context, not an exploit release, and a new exploit would not lower risk.
T-12

What is a tool like OpenVAS primarily used for in cybersecurity?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APassword cracking recovers passwords from hashes, using tools such as John the Ripper or Hashcat, not OpenVAS.
  2. BSession hijacking takes over an authenticated session and is unrelated to what OpenVAS does.
  3. CCorrect: OpenVAS, now part of Greenbone, is an open-source scanner that tests hosts against a feed of known vulnerability checks.
  4. DPenetration testing includes exploitation and manual analysis, whereas OpenVAS automates the vulnerability detection piece.
T-13

What is the term for the methodology used to detect, analyze, and mitigate security vulnerabilities in a computer system?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AIncident management handles security events after they occur, rather than the ongoing cycle of finding and fixing weaknesses.
  2. BPenetration testing is a point-in-time exercise that exploits weaknesses, not the continuous lifecycle of tracking and mitigating them.
  3. CCorrect: vulnerability management is the continuous cycle of identifying, assessing, prioritizing, remediating and verifying vulnerabilities.
  4. DRisk assessment evaluates likelihood and impact across threats broadly, and is one input rather than the full detect-to-mitigate cycle.
T-14

An analyst's risk report lists a recently patched vulnerability as active, but assigns it a low Environmental CVSS score specifically because the patch was applied. What conceptual error did the analyst make?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARemediation status is not what temporal metrics track, and patching does not automatically zero them.
  2. BBase metrics describe the flaw's intrinsic nature and are not edited to reflect a host's patch state.
  3. CPatch status is not represented by the exploitability subscore, so adjusting it misstates the situation.
  4. DCorrect: environmental metrics express the asset's business importance and exposure, not whether a patch was applied, so a remediated flaw should be closed rather than scored down.
T-15

Which type of attack capitalizes on the default settings and configurations that are found in many newly installed network devices?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA zero-day exploits a flaw unknown to the vendor, not settings left unchanged after installation.
  2. BApplication-level attacks target flaws in application code, not factory defaults on network devices.
  3. CCorrect: out-of-the-box configuration weaknesses, such as default credentials and open services, are exploited because devices are deployed without hardening.
  4. DSocial engineering manipulates people into revealing information or taking actions, rather than exploiting device configuration.

Where vulnerability analysis gets misread

Is vulnerability analysis the same as a penetration test?

No. Analysis identifies and ranks weaknesses; a penetration test tries to prove which ones are actually exploitable.

Which CVSS version should I study?

Both v3.1 and v4.0 are in circulation, and v4.0 is the current specification at FIRST (as of Oct 11, 2026). Learn what a base score expresses and how CVE, CVSS and NVD relate, which the table above lays out.

Sources