nerdexam
EC-Council

312-50V12 · Question #45

David is a security professional working in an organization, and he is implementing a vulnerability management program in the organization to evaluate and control the risks and vulnerabilities in its

The correct answer is A. Remediation. The vulnerability management life cycle includes distinct phases, and applying fixes (patches) to vulnerable systems specifically corresponds to the Remediation phase.

Submitted by yasin.bd· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

David is a security professional working in an organization, and he is implementing a vulnerability management program in the organization to evaluate and control the risks and vulnerabilities in its IT infrastructure. He is currently executing the process of applying fixes on vulnerable systems to reduce the impact and severity of vulnerabilities. Which phase of the vulnerability-management life cycle is David currently in?

Options

  • ARemediation
  • BVerification
  • CRisk assessment
  • DVulnerability scan

How the community answered

(25 responses)
  • A
    96% (24)
  • D
    4% (1)

Why each option

The vulnerability management life cycle includes distinct phases, and applying fixes (patches) to vulnerable systems specifically corresponds to the Remediation phase.

ARemediationCorrect

Remediation is the phase in the vulnerability management life cycle where identified vulnerabilities are addressed by applying patches, configuration changes, or other fixes to reduce their impact and severity. David is actively deploying fixes to vulnerable systems, which is the defining activity of the remediation phase. This phase occurs after vulnerabilities have been identified and prioritized, and before verification confirms the fixes were successful.

BVerification

Verification is the phase that comes after remediation, where security teams confirm that the applied fixes successfully resolved the vulnerabilities and that no new issues were introduced.

CRisk assessment

Risk assessment is an earlier phase in the life cycle focused on evaluating the likelihood and potential impact of vulnerabilities, not on actively applying fixes to systems.

DVulnerability scan

Vulnerability scanning is the phase focused on using automated tools to discover and identify vulnerabilities present in the IT infrastructure, not on applying corrective fixes.

Concept tested: Vulnerability management life cycle phase identification

Source: https://www.nist.gov/publications/guide-enterprise-patch-management-planning-preventive-maintenance-software

Topics

#Vulnerability management#Remediation#Security operations#Risk management

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice