// PATH EXAM

📡 Vulnerabilities & threat intel

8 questions; you pass with 6. It is graded on the server and you will only see your score. If you pass, you can issue your certificate. Review the path first

1. Your package-lock.json has lodash 4.17.11, with a vulnerability fixed in 4.17.21. What do you do?
2. What is a "0-day"?
3. Why is sorting by CVSS not enough to decide what to patch first?
4. What does the CVSS PR (Privileges Required) metric measure?
5. What does CVSS measure?
6. What is OSV.dev?
7. One vulnerability has CVSS 9.8 and no known exploit; another has CVSS 7.5 and is in KEV. Which do you patch first?
8. What is a CVE identifier?