nerdexam
Isaca

CRISC · Question #278

Which of the following is the BEST way to validate whether controls to reduce user device vulnerabilities have been implemented according to management's action plan?

The correct answer is B. Rescan the user environment.. The best way to validate that controls for user device vulnerabilities have been implemented according to a plan is to rescan the environment to objectively verify vulnerability reduction.

Submitted by viktor_hu· Apr 18, 2026Risk Response and Reporting

Question

Which of the following is the BEST way to validate whether controls to reduce user device vulnerabilities have been implemented according to management's action plan?

Options

  • ASurvey device owners.
  • BRescan the user environment.
  • CRequire annual end user policy acceptance.
  • DReview awareness training assessment results

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    80% (36)
  • C
    11% (5)
  • D
    7% (3)

Why each option

The best way to validate that controls for user device vulnerabilities have been implemented according to a plan is to rescan the environment to objectively verify vulnerability reduction.

ASurvey device owners.

Surveying device owners provides subjective feedback on whether they *think* controls are implemented or effective, but it does not offer objective proof of actual vulnerability reduction.

BRescan the user environment.Correct

Rescanning the user environment provides objective, technical evidence of whether vulnerabilities on user devices have actually been reduced or remediated as a result of the implemented controls. This direct verification offers concrete proof of the controls' effectiveness in meeting the action plan's technical objectives.

CRequire annual end user policy acceptance.

Requiring annual policy acceptance ensures users acknowledge rules, but it does not validate the technical implementation or effectiveness of controls designed to reduce device vulnerabilities.

DReview awareness training assessment results

Reviewing awareness training assessment results measures user understanding, which relates to human-centric vulnerabilities, but not the technical reduction of device vulnerabilities through controls.

Concept tested: Control validation, vulnerability management, security scanning

Source: https://csrc.nist.gov/publications/detail/sp/800-40/rev-3/final

Topics

#Control validation#Vulnerability management#Security controls#Implementation verification

Community Discussion

No community discussion yet for this question.

Full CRISC Practice