312-50V12 · Question #45
David is a security professional working in an organization, and he is implementing a vulnerability management program in the organization to evaluate and control the risks and vulnerabilities in its
The correct answer is A. Remediation. The vulnerability management life cycle includes distinct phases, and applying fixes (patches) to vulnerable systems specifically corresponds to the Remediation phase.
Question
Options
- ARemediation
- BVerification
- CRisk assessment
- DVulnerability scan
How the community answered
(25 responses)- A96% (24)
- D4% (1)
Why each option
The vulnerability management life cycle includes distinct phases, and applying fixes (patches) to vulnerable systems specifically corresponds to the Remediation phase.
Remediation is the phase in the vulnerability management life cycle where identified vulnerabilities are addressed by applying patches, configuration changes, or other fixes to reduce their impact and severity. David is actively deploying fixes to vulnerable systems, which is the defining activity of the remediation phase. This phase occurs after vulnerabilities have been identified and prioritized, and before verification confirms the fixes were successful.
Verification is the phase that comes after remediation, where security teams confirm that the applied fixes successfully resolved the vulnerabilities and that no new issues were introduced.
Risk assessment is an earlier phase in the life cycle focused on evaluating the likelihood and potential impact of vulnerabilities, not on actively applying fixes to systems.
Vulnerability scanning is the phase focused on using automated tools to discover and identify vulnerabilities present in the IT infrastructure, not on applying corrective fixes.
Concept tested: Vulnerability management life cycle phase identification
Source: https://www.nist.gov/publications/guide-enterprise-patch-management-planning-preventive-maintenance-software
Topics
Community Discussion
No community discussion yet for this question.