nerdexam
CompTIA

CS0-003 · Question #306

Which of the following is a useful tool for mapping, tracking, and mitigating identified threats and vulnerabilities with the likelihood and impact of occurrence?

The correct answer is A. Risk register. Risk Register is the correct answer because it is a formal document used to identify, track, and prioritize risks by recording details such as threat descriptions, likelihood of occurrence, potential impact, and mitigation strategies - making it a comprehensive management tool…

Submitted by tom_us· Mar 6, 2026Vulnerability Management

Question

Which of the following is a useful tool for mapping, tracking, and mitigating identified threats and vulnerabilities with the likelihood and impact of occurrence?

Options

  • ARisk register
  • BVulnerability assessment
  • CPenetration test
  • DCompliance report

How the community answered

(67 responses)
  • A
    91% (61)
  • B
    1% (1)
  • C
    4% (3)
  • D
    3% (2)

Explanation

Risk Register is the correct answer because it is a formal document used to identify, track, and prioritize risks by recording details such as threat descriptions, likelihood of occurrence, potential impact, and mitigation strategies - making it a comprehensive management tool for ongoing risk oversight.

A vulnerability assessment (B) is a process for discovering weaknesses in systems, but it does not provide a structured framework for tracking likelihood, impact, and mitigation over time. A penetration test (C) actively simulates attacks to exploit vulnerabilities, but like a vulnerability assessment, it is a point-in-time activity rather than a living tracking tool. A compliance report (D) measures adherence to regulatory standards and policies, not the mapping and mitigation of threats and vulnerabilities.

Memory Tip: Think of a Risk Register as a "risk diary" - it continuously logs and monitors threats, much like a project manager's log that tracks problems from discovery to resolution. If the question mentions tracking + likelihood + impact, always think Register (a running record).

Topics

#Risk register#Risk management#Vulnerability management#Threat management

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice