CISSP · Question #551
What is the MOST common component of a vulnerability management framework?
The correct answer is B. Patch management. Vulnerability management frameworks are built around identifying, prioritizing, and remediating security weaknesses in systems, with patch management being the central operational component.
Question
Options
- ARisk analysis
- BPatch management
- CThreat analysis
- DBackup management
How the community answered
(51 responses)- A8% (4)
- B86% (44)
- C2% (1)
- D4% (2)
Why each option
Vulnerability management frameworks are built around identifying, prioritizing, and remediating security weaknesses in systems, with patch management being the central operational component.
Risk analysis is a broader enterprise risk management activity that evaluates likelihood and impact of threats, and while it informs vulnerability prioritization, it is not the core operational component of a vulnerability management framework.
Patch management is the most common and foundational component of a vulnerability management framework because it directly addresses the remediation phase - applying software updates and fixes to close identified vulnerabilities. Without patch management, vulnerabilities remain exploitable even after they are discovered and analyzed. Most vulnerability management lifecycles (as defined by NIST and other frameworks) culminate in remediation through patching as the primary corrective action.
Threat analysis focuses on identifying and understanding potential threat actors and attack vectors, which is part of threat intelligence rather than the day-to-day operational workflow of vulnerability management.
Backup management is a data protection and business continuity practice concerned with recovery from data loss events, and is not a component of vulnerability management frameworks.
Concept tested: Core components of vulnerability management frameworks
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf
Topics
Community Discussion
No community discussion yet for this question.