712-50 · Question #52
Within an organization's vulnerability management program, who has the responsibility to implement remediation actions?
The correct answer is D. System administrator. System administrators are correct (D) because they are the technical custodians of the systems where vulnerabilities exist - they have the access, tools, and hands-on authority to apply patches, change configurations, and execute the actual fixes. The security officer (A) sets…
Question
Within an organization's vulnerability management program, who has the responsibility to implement remediation actions?
Options
- ASecurity officer
- BData owner
- CVulnerability engineer
- DSystem administrator
How the community answered
(35 responses)- A14% (5)
- B3% (1)
- C6% (2)
- D77% (27)
Explanation
System administrators are correct (D) because they are the technical custodians of the systems where vulnerabilities exist - they have the access, tools, and hands-on authority to apply patches, change configurations, and execute the actual fixes. The security officer (A) sets policy and oversees the program but delegates implementation to technical staff. The data owner (B) is accountable for data classification and business risk decisions, not technical system maintenance. The vulnerability engineer (C) identifies and assesses vulnerabilities but typically hands off remediation tasks rather than performing them directly.
Memory tip: Think "who has the keys to the server room?" - the sysadmin does. They're the ones running apt upgrade or deploying the patch, not the security officer writing the policy.
Topics
Community Discussion
No community discussion yet for this question.