Bookmark this page

Quiz: Managing Security and Risk

Choose the correct answers to the following questions:

  1. 1.

    Which security management life-cycle component recommends revising, updating, and remediating changes?

    A

    Build

    B

    Run

    C

    Manage

    D

    Adapt

    E

    Design

  2. 2.

    Which email address is used when reporting any suspected security vulnerability in a Red Hat product or service to Red Hat Product Security?

    A

    B

    C

    D

  3. 3.

    Which three statements describe a critical impact severity classification? (Choose three.)

    A

    Requires an authenticated remote user.

    B

    Does not require user interaction to invoke a possible system compromise by arbitrary code execution.

    C

    Exposes a vulnerability that can be exploited by worms.

    D

    Requires a local user.

    E

    Is easily exploited by an unauthenticated attacker.

  4. 4.

    Which two statements apply to Red Hat backporting of security fixes? (Choose two.)

    A

    Red Hat follows the same procedures as common proprietary software updates.

    B

    Red Hat takes a fix for a security flaw out of the most recent version of an upstream software package and applies that fix to an earlier version of the package that Red Hat distributes.

    C

    Red Hat discovers a fix for a security flaw out of the most recent version of a production software package and generates an advisory for all upstream distributions.

    D

    Red Hat ensures the fixes do not introduce unwanted side effects.

  5. 5.

    Red Hat uses what industry standard numbering and naming to consistently report and track security-related software issues?

    A

    Customized email notifications from the bug-tracking team

    B

    Common Vulnerabilities and Exposures (CVE)

    C

    Common Vulnerability Scoring System (CVSS)

    D

    Red Hat Security Vulnerability Response (RHSVR)

  6. 6.

    Which yum command provides an update information summary report for all security classification notices for a system?

    A

    yum updateinfo --security

    B

    yum checkupdates --security

    C

    yum list-updates --security

    D

    yum update-info --security

    E

    yum list-security --updates

Revision: rh415-7.5-813735c