nerdexam
Isaca

CISM · Question #421

A software bug reported by external sources should trigger which of the following processes to assess the affected applications?

The correct answer is C. Vulnerability management. When a software bug is reported by external sources, it should trigger the vulnerability management process, which involves identifying, assessing, prioritizing, and remediating vulnerabilities in affected applications. This ensures that security risks are properly managed and mi

Submitted by stefanr· Apr 18, 2026Information Security Risk Management

Question

A software bug reported by external sources should trigger which of the following processes to assess the affected applications?

Options

  • AContinuous improvement
  • BRoot cause analysis
  • CVulnerability management
  • DProblem management

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    15% (6)
  • C
    78% (31)
  • D
    3% (1)

Explanation

When a software bug is reported by external sources, it should trigger the vulnerability management process, which involves identifying, assessing, prioritizing, and remediating vulnerabilities in affected applications. This ensures that security risks are properly managed and mitigated. While root cause analysis and problem management help in identifying underlying issues, vulnerability management is the most relevant process for assessing security risks related to software bugs.

Topics

#Vulnerability management#Software bugs#Application assessment#External reports

Community Discussion

No community discussion yet for this question.

Full CISM Practice