nerdexam
EC-Council

112-52 · Question #42

Which activity is part of a vulnerability assessment process?

The correct answer is A. Identifying vulnerabilities. Identifying vulnerabilities (A) is the core activity of a vulnerability assessment - the process systematically scans systems, networks, or applications to discover weaknesses before attackers can exploit them. Why the distractors are wrong: B (Exploiting vulnerabilities)…

Information Gathering and Vulnerability Analysis

Question

Which activity is part of a vulnerability assessment process?

Options

  • AIdentifying vulnerabilities
  • BExploiting vulnerabilities for access
  • CEncrypting databases
  • DInstalling operating systems

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    7% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Identifying vulnerabilities (A) is the core activity of a vulnerability assessment - the process systematically scans systems, networks, or applications to discover weaknesses before attackers can exploit them.

Why the distractors are wrong:

  • B (Exploiting vulnerabilities) describes penetration testing, a separate, more aggressive activity that goes beyond assessment into active attack simulation.
  • C (Encrypting databases) is a security hardening/mitigation control, not part of the discovery process.
  • D (Installing operating systems) is a systems administration task with no direct connection to vulnerability assessment.

Memory tip: Think of vulnerability assessment as a doctor's checkup - you identify what's wrong, you don't perform surgery. The moment you start exploiting (operating), you've crossed into pen testing territory.

Topics

#vulnerability assessment#vulnerability identification#security testing#vulnerability management

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice