
CompTIASecurityX (CASP+)
Domain 3Objective 2
Vulnerability Management CAS-005 Practice Questions (Page 2)
Part of the Security engineering domain, which accounts for 31% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–34 in this domain), expect 4–7 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
8concepts
31%of the exam
Questions 6–10
- 6
A security analyst is planning a vulnerability scan of a mixed environment that includes Windows servers, Linux servers, and network devices. The scan must be authenticated to reduce false positives and must not disrupt critical production services. Which approach should the analyst take?
Select an answer first - 7
A vulnerability scanner is configured to identify systems running a specific version of a web server. The scanner uses CPE to identify the software. The analyst notices that some systems are not being identified correctly. What is the most likely cause?
Select an answer first - 8
What is the primary purpose of the Security Content Automation Protocol (SCAP)?
Select an answer first - 9
What is the primary purpose of the Common Vulnerability Scoring System (CVSS)?
Select an answer first - 10
A security analyst is reviewing a vulnerability report and sees a reference to 'CVE-2024-1234'. The analyst needs to understand the severity of this vulnerability and whether it applies to their systems. Which two pieces of information should the analyst look up?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.