Searching CertSprout…
Searching CertSprout…
A little curiosity goes a long way
Search certifications, learning topics, career paths, public profiles and help across CertSprout.
Showing 20 results · Page 3 for “vulnerability”. More results are available below.
CCOA · Vulnerability management
A vulnerability score describes technical severity but does not fully describe the organization's risk. Add asset importance, reachability, exploitation evidence and existing controls to the…
CESP-ADCS · Directory security assessment
…es can remove an escalation path even when no software vulnerability is involved. Worked example An ordinary directory user can reset a privileged service account's password. What should an …
CETP · Directory security assessment
…es can remove an escalation path even when no software vulnerability is involved. Worked example An ordinary directory user can reset a privileged service account's password. What should an …
CJDE · Security monitoring
…e A detection rule generates many alerts from approved vulnerability scans. What is the best tuning approach? Use verified scanner context with narrow exceptions Scoped tuning reduces known …
CNVP · Authorized penetration testing
A penetration test starts with explicit scope, permitted techniques, timing and stop conditions. These boundaries protect operations and make results interpretable. Demonstrate the impact ne…
CNVP · Security findings and communication
A useful security finding connects an affected asset, the observed weakness, the conditions for exploitation and the resulting impact. Include enough reproducible evidence to verify the conc…
CNVP · Vulnerability management
A vulnerability score describes technical severity but does not fully describe the organization's risk. Add asset importance, reachability, exploitation evidence and existing controls to the…
CRTE · Directory security assessment
…es can remove an escalation path even when no software vulnerability is involved. Worked example An ordinary directory user can reset a privileged service account's password. What should an …
CRTM · Directory security assessment
…es can remove an escalation path even when no software vulnerability is involved. Worked example An ordinary directory user can reset a privileged service account's password. What should an …
CRTP · Directory security assessment
…es can remove an escalation path even when no software vulnerability is involved. Worked example An ordinary directory user can reset a privileged service account's password. What should an …
CySA+ · Vulnerability Management
An unauthenticated scan probes a host from the network, fingerprinting services and banners the way an external attacker would. It is quick and needs no access, but it guesses at versions an…
CySA+ · Vulnerability Management
The Common Vulnerability Scoring System base score combines exploitability metrics, attack vector, attack complexity, privileges required and user interaction, with impact metrics for confid…
CySA+ · Vulnerability Management
Every scanner finding or alert falls into one of four boxes. A true positive is a real issue correctly reported. A false positive is a report of something that is not actually there, wasting…
CySA+ · Vulnerability Management
Some systems cannot be fixed on schedule, whether an unsupported medical device, an industrial controller or an application whose vendor is gone. Compensating controls reduce the exploitabil…
CySA+ · Vulnerability Management
Static application security testing analyzes source code or compiled binaries without running them, catching insecure functions, hard-coded secrets and taint flows from input to dangerous si…
CySA+ · Vulnerability Management
Cross-site scripting appears as script tags or event handlers in parameters and is fixed by output encoding and content security policy. SQL injection shows single quotes, OR 1=1, UNION SELE…
CySA+ · Vulnerability Management
A zero-day vulnerability is one the vendor has had zero days to fix, either because it is being exploited before disclosure or because it was published without warning. The exposure window c…
CySA+ · Incident Response and Management
…scheduled tasks and registry run keys, and closing the vulnerability that let the attacker in. Rebuilding from known-good images is often safer than cleaning. Recovery then restores systems …
CySA+ · Reporting and Communication
A vulnerability or incident report fails when it hands the board a list of CVEs or hands an administrator a paragraph about brand impact. Executive summaries state what happened or was found…
CySA+ · Reporting and Communication
Mean time to detect measures how long a threat or vulnerability exists before the organization notices it. Mean time to remediate measures how long from discovery to fix, usually reported pe…
People search uses public names, handles and headlines. Private and unlisted profiles are excluded. Your goals are visible only to you in search.