nerdexam
(ISC)2

CISSP · Question #551

What is the MOST common component of a vulnerability management framework?

The correct answer is B. Patch management. Vulnerability management frameworks are built around identifying, prioritizing, and remediating security weaknesses in systems, with patch management being the central operational component.

Submitted by carlos_mx· Mar 5, 2026Security Operations

Question

What is the MOST common component of a vulnerability management framework?

Options

  • ARisk analysis
  • BPatch management
  • CThreat analysis
  • DBackup management

How the community answered

(51 responses)
  • A
    8% (4)
  • B
    86% (44)
  • C
    2% (1)
  • D
    4% (2)

Why each option

Vulnerability management frameworks are built around identifying, prioritizing, and remediating security weaknesses in systems, with patch management being the central operational component.

ARisk analysis

Risk analysis is a broader enterprise risk management activity that evaluates likelihood and impact of threats, and while it informs vulnerability prioritization, it is not the core operational component of a vulnerability management framework.

BPatch managementCorrect

Patch management is the most common and foundational component of a vulnerability management framework because it directly addresses the remediation phase - applying software updates and fixes to close identified vulnerabilities. Without patch management, vulnerabilities remain exploitable even after they are discovered and analyzed. Most vulnerability management lifecycles (as defined by NIST and other frameworks) culminate in remediation through patching as the primary corrective action.

CThreat analysis

Threat analysis focuses on identifying and understanding potential threat actors and attack vectors, which is part of threat intelligence rather than the day-to-day operational workflow of vulnerability management.

DBackup management

Backup management is a data protection and business continuity practice concerned with recovery from data loss events, and is not a component of vulnerability management frameworks.

Concept tested: Core components of vulnerability management frameworks

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf

Topics

#vulnerability management#patch management#security operations#risk mitigation

Community Discussion

No community discussion yet for this question.

Full CISSP Practice