nerdexam
EC-Council

712-50 · Question #52

Within an organization's vulnerability management program, who has the responsibility to implement remediation actions?

The correct answer is D. System administrator. System administrators are correct (D) because they are the technical custodians of the systems where vulnerabilities exist - they have the access, tools, and hands-on authority to apply patches, change configurations, and execute the actual fixes. The security officer (A) sets…

Security Program Management & Operations

Question

Within an organization's vulnerability management program, who has the responsibility to implement remediation actions?

Options

  • ASecurity officer
  • BData owner
  • CVulnerability engineer
  • DSystem administrator

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    6% (2)
  • D
    77% (27)

Explanation

System administrators are correct (D) because they are the technical custodians of the systems where vulnerabilities exist - they have the access, tools, and hands-on authority to apply patches, change configurations, and execute the actual fixes. The security officer (A) sets policy and oversees the program but delegates implementation to technical staff. The data owner (B) is accountable for data classification and business risk decisions, not technical system maintenance. The vulnerability engineer (C) identifies and assesses vulnerabilities but typically hands off remediation tasks rather than performing them directly.

Memory tip: Think "who has the keys to the server room?" - the sysadmin does. They're the ones running apt upgrade or deploying the patch, not the security officer writing the policy.

Topics

#Vulnerability Management#Remediation Implementation#System Administration#Risk Management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice