nerdexam
GIAC

GSLC · Question #448

What are the steps related to the vulnerability management program? Each correct answer represents a complete solution. Choose all that apply.

The correct answer is A. Baseline the Environment B. Maintain and Monitor D. Define Policy. A formal vulnerability management program requires defining policy, baselining the environment, and ongoing maintenance and monitoring - 'Organization Vulnerability' is not a recognized program phase.

Security Operations & Incident Response Leadership

Question

What are the steps related to the vulnerability management program? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ABaseline the Environment
  • BMaintain and Monitor
  • COrganization Vulnerability
  • DDefine Policy

How the community answered

(27 responses)
  • A
    93% (25)
  • C
    7% (2)

Why each option

A formal vulnerability management program requires defining policy, baselining the environment, and ongoing maintenance and monitoring - 'Organization Vulnerability' is not a recognized program phase.

ABaseline the EnvironmentCorrect

Baselining the Environment documents the current security posture of all systems and assets, creating a reference point against which future vulnerability scans and changes can be measured.

BMaintain and MonitorCorrect

Maintain and Monitor is a continuous phase where the organization performs recurring scans, tracks remediation status, and validates that controls remain effective as the environment evolves.

COrganization Vulnerability

'Organization Vulnerability' is not a defined or recognized phase in any established vulnerability management framework such as NIST SP 800-40 or CVSS-based lifecycle models.

DDefine PolicyCorrect

Define Policy is the foundational step that establishes the program scope, risk tolerance, roles, responsibilities, and remediation timelines that govern all subsequent vulnerability management activities.

Concept tested: Vulnerability management program lifecycle phases

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf

Topics

#vulnerability management#security baseline#policy definition#security monitoring

Community Discussion

No community discussion yet for this question.

Full GSLC Practice