nerdexam
EC-Council

112-52 · Question #135

Which of the following is typically identified during a vulnerability assessment?

The correct answer is B. Outdated software versions. Vulnerability assessments are automated or manual technical scans of systems that identify known weaknesses in software, configurations, and infrastructure - outdated software versions (B) are a classic output, since unpatched software has known CVEs that scanners directly detect

Information Gathering and Vulnerability Analysis

Question

Which of the following is typically identified during a vulnerability assessment?

Options

  • AEmployee susceptibility to phishing
  • BOutdated software versions
  • CSecurity awareness training gaps
  • DEncryption standards in use

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    93% (39)
  • D
    2% (1)

Explanation

Vulnerability assessments are automated or manual technical scans of systems that identify known weaknesses in software, configurations, and infrastructure - outdated software versions (B) are a classic output, since unpatched software has known CVEs that scanners directly detect.

Why the distractors are wrong:

  • A (Phishing susceptibility) - This is identified through phishing simulations or social engineering tests, not vulnerability assessments.
  • C (Security awareness training gaps) - These are uncovered through security audits, surveys, or training program reviews, which are people/process-focused rather than technical.
  • D (Encryption standards in use) - Documenting what encryption is deployed is part of a security audit or compliance review, not something a vulnerability scanner flags as a finding.

Memory tip: Think of vulnerability assessments as "scanner-finds-CVEs" tools - they match your system's software inventory against databases of known vulnerabilities. Outdated software = known CVE = scanner finding. Anything involving people behavior or policy documentation belongs to a different assessment type.

Topics

#vulnerability assessment#software vulnerabilities#patch management#threat identification

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice