712-50 · Question #226
What is the FIRST step in developing the vulnerability management program?
The correct answer is A. Baseline the Environment. Baselining the environment must come first because you cannot manage what you don't know exists. Before policies can be enforced or vulnerabilities prioritized, you need a complete, accurate inventory of all assets, systems, and their current security state - this snapshot…
Question
What is the FIRST step in developing the vulnerability management program?
Options
- ABaseline the Environment
- BMaintain and Monitor
- COrganization Vulnerability
- DDefine Policy
How the community answered
(31 responses)- A81% (25)
- B10% (3)
- C6% (2)
- D3% (1)
Explanation
Baselining the environment must come first because you cannot manage what you don't know exists. Before policies can be enforced or vulnerabilities prioritized, you need a complete, accurate inventory of all assets, systems, and their current security state - this snapshot becomes the foundation every subsequent step builds on.
Why the distractors are wrong:
- B (Maintain and Monitor) is a late-stage, ongoing activity - you can only monitor against a known baseline, so it can't come first.
- C (Organization Vulnerability) - identifying organizational vulnerabilities is part of the assessment phase, which itself depends on a baseline already being in place.
- D (Define Policy) is important, but policy without knowing what you're protecting is abstract; in practice, the baseline informs what the policy needs to cover.
Memory tip: Think of it like painting a house - you can't know how much paint to buy (policy), which rooms need the most work (org vulnerabilities), or track progress (monitor) until you first walk through every room and take stock (baseline). Baseline = inventory first, everything else second.
Topics
Community Discussion
No community discussion yet for this question.