nerdexam
EC-Council

312-50V12 · Question #271

Given below are different steps involved in the vulnerability-management life cycle. 1) Remediation 2) Identify assets and create a baseline 3) Verification 4) Monitor 5) Vulnerability scan 6) Risk…

The correct answer is A. 2 → 5 → 6 → 1 → 3 → 4. The vulnerability management life cycle follows a structured sequence: identify assets, scan for vulnerabilities, assess risk, remediate, verify fixes, and continuously monitor. Understanding this order is critical for effective security operations.

Submitted by tom_us· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

Given below are different steps involved in the vulnerability-management life cycle. 1) Remediation 2) Identify assets and create a baseline 3) Verification 4) Monitor 5) Vulnerability scan 6) Risk assessment Identify the correct sequence of steps involved in vulnerability management.

Options

  • A2 → 5 → 6 → 1 → 3 → 4
  • B2 → 4 → 5 → 3 → 6 → 1
  • C2 → 1 → 5 → 6 → 4 → 3
  • D1 → 2 → 3 → 4 → 5 → 6

How the community answered

(43 responses)
  • A
    95% (41)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The vulnerability management life cycle follows a structured sequence: identify assets, scan for vulnerabilities, assess risk, remediate, verify fixes, and continuously monitor. Understanding this order is critical for effective security operations.

A2 → 5 → 6 → 1 → 3 → 4Correct

The correct sequence begins with identifying assets and creating a baseline (2) to know what needs protection, followed by a vulnerability scan (5) to discover weaknesses, then risk assessment (6) to prioritize findings by impact, remediation (1) to fix the identified issues, verification (3) to confirm fixes were successful, and finally ongoing monitoring (4) to detect new threats - forming a continuous improvement cycle.

B2 → 4 → 5 → 3 → 6 → 1

This sequence incorrectly places monitoring (4) before the vulnerability scan (5) and omits risk assessment before remediation, meaning vulnerabilities would not be prioritized by risk before action is taken.

C2 → 1 → 5 → 6 → 4 → 3

This sequence places remediation (1) immediately after asset identification before any scanning or risk assessment has occurred, making it impossible to know what needs to be fixed or how urgently.

D1 → 2 → 3 → 4 → 5 → 6

This sequence starts with remediation (1) before assets have even been identified or scanned, which is logically impossible and violates the foundational structure of the vulnerability management process.

Concept tested: Vulnerability management life cycle correct sequence

Source: https://www.nist.gov/publications/technical-guide-information-security-testing-and-assessment

Topics

#vulnerability management lifecycle#remediation#risk assessment#vulnerability scanning

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice