Ethical › Module 5 › Lesson 5
Quiz — Vulnerability Analysis
10 APPLY questions on CVE/CVSS and ethical handling of findings.
Opening
Vulnerability analysis — Module Quiz
Ten APPLY items on the sentences this module refused to collapse: a CVE is a catalog name for a bug (CVE-YEAR-NUMBER plus an advisory); a CVSS vector is literacy (network vs local, impact), not a spell; a scanner row is a fingerprint hypothesis, not confirmed risk and not automatic remote code execution; false positives and missing inventory/exposure are why you verify only on systems you own; localhost python http.server is not Log4Shell (CVE-2021-44228) and not Heartbleed (CVE-2014-0160); risk treatment is patch, compensate, or accept with a written owner, a date, and a check that is not a proof-of-concept. Cyberlium’s artifact is $HOME/cyberlium-lab notes (cve-literacy, scanner-vs-risk, risk-treatment, cve-fix-note) chmod 600. Public NVD/vendor pages only. Nessus-against-the-internet, café scans, exploit clones, searchsploit runs, Metasploit screenshots titled remediation, and nmap of strangers are all failing answers even when they look “more CEH.” This path is original Cyberlium teaching mapped to the CEH v13 vulnerability-analysis domain — not official EC-Council training, not a certification, not exam dumps. Wrong answers still teach. Empty ethics lines fail. Next after this quiz is Access, Credentials, and Why Hashes Matter: Module 6 talks hashes and MFA as defense, not as a cracking kit — still no payloads, still no hashcat.
Knowledge Check
APPLY: A teammate pastes CVE-2021-44228 into chat, opens Metasploit, and wants to scan random IPs “because NVD says it is bad.” What is a CVE here, and what do you do?
Multiple choice
Knowledge Check
APPLY: True or False: If a scanner lists a CVE next to a banner you saw on localhost http.server, you have proven remote code execution and should Nessus-scan the café for more copies.
True or False
Knowledge Check
APPLY: Why can a red scanner cell be a false positive, and where does verification happen?
Multiple choice
Knowledge Check
APPLY: A CVSS vector on NVD shows a high network score for a well-known CVE. What is the literate reading, and what is not?
Multiple choice
Knowledge Check
APPLY: Select treatments that match “risk treatment with an owner” on a system you own (or a labeled hypothetical you own). (Select 2)
Select all that apply
Knowledge Check
APPLY: You opened a public NVD page for CVE-2014-0160 as literacy. Which lab pairing is required?
Multiple choice
Knowledge Check
APPLY: True or False: Compensating for a finding means hiding banners, skipping owners, and verifying with a proof-of-concept against localhost http.server.
True or False
Knowledge Check
APPLY: A blog titled with a cert acronym publishes “vuln analysis” as nuclei against 0.0.0.0/0 plus hashcat. What does Cyberlium Module 5 tell you?
Multiple choice
Knowledge Check
APPLY: You finished cve-fix-note.txt. Which hygiene and ethics pairing is required before the quiz badge?
Multiple choice
Knowledge Check
APPLY: You carry Module 5 into Module 6. Which pairing is true, and what opens after this quiz?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a home router login (TP-Link / Netgear / Huawei / "Router Admin"). Is that DEMO in scope as a hacking target?
Multiple choice
Answer all 11 knowledge checks to continue. (0/11 answered)