Reconcile an authenticated assessment coverage ledger

A hands-on CS0-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CS0-004 practice

Certification
CS0-004
Format
SQL query
Difficulty
hard
Estimated time
35 min
Automated checks
8

The brief

Repair coverage.sql. Return exactly asset_id, owner, coverage_status, attempt_id, assessed_second, high_findings, with one row per inventory asset; repeated identical imported rows must not multiply the ledger. Preserve the inventory owner, including an unknown NULL owner. scope_state excluded means EXCLUDED; pending means AUTHORIZATION_PENDING. Both retain NULL attempt/time and zero findings, even if old scan records exist. Never silently remove an unassessed or excluded inventory asset. For approved assets, assessment evidence is eligible only when outcome='complete', authenticated=1 and inventory_collected=1. At the fixed observation second 1000, finished must be in the inclusive 700..1000 window. Select the newest eligible finished value; a later failed attempt does not erase an earlier still-current successful assessment. If times tie, select the lexicographically greatest attempt_id. Missing eligible evidence means NOT_ASSESSED, NULL attempt/time and zero findings; otherwise report ASSESSED with that actual attempt and finished time. Zero findings from failed credentials or missing inventory must not become an assessed result. high_findings counts distinct finding_id values only for that selected attempt AND that asset, with confirmed=1 and severity>=7. Imported duplicates, another asset's records and older scan findings must not inflate it. The threshold is this team's policy, not an exploitation verdict. A window-ranked eligible-attempt query or an equivalent correlated/anti-join selection is valid. Inspect actual inventory status, chosen attempt and finding counts; repair a newly visible stale or duplicate-evidence error without Reset.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • One bounded read-only evidence query executes across the supplied immutable schemas.
  • The query exposes exactly the six declared ledger columns in their declared order.
  • Every unique inventory asset remains represented with its owner and explicit excluded/pending/unassessed disposition.
  • Only completed authenticated attempts with collected inventory support assessed status.
  • The newest eligible as-of assessment remains selected across failures, expiry and inclusive freshness boundaries.
  • Count only confirmed threshold findings attached to both the selected attempt and the actual asset.
  • Imported copies do not multiply rows or findings, and equal-time assessments use the declared ID tie-break.
  • The same evidence semantics work for previously unseen assets, owners and legitimate zero-finding assessed outcomes.

Where this sits in the CS0-004 blueprint

Domain
Vulnerability Management
Objective
Vulnerability Scanning Methods
Skill
Safe Scan Scope and Access

Part of CS0-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.