GSLC · Question #448
What are the steps related to the vulnerability management program? Each correct answer represents a complete solution. Choose all that apply.
The correct answer is A. Baseline the Environment B. Maintain and Monitor D. Define Policy. A formal vulnerability management program requires defining policy, baselining the environment, and ongoing maintenance and monitoring - 'Organization Vulnerability' is not a recognized program phase.
Question
What are the steps related to the vulnerability management program? Each correct answer represents a complete solution. Choose all that apply.
Options
- ABaseline the Environment
- BMaintain and Monitor
- COrganization Vulnerability
- DDefine Policy
How the community answered
(27 responses)- A93% (25)
- C7% (2)
Why each option
A formal vulnerability management program requires defining policy, baselining the environment, and ongoing maintenance and monitoring - 'Organization Vulnerability' is not a recognized program phase.
Baselining the Environment documents the current security posture of all systems and assets, creating a reference point against which future vulnerability scans and changes can be measured.
Maintain and Monitor is a continuous phase where the organization performs recurring scans, tracks remediation status, and validates that controls remain effective as the environment evolves.
'Organization Vulnerability' is not a defined or recognized phase in any established vulnerability management framework such as NIST SP 800-40 or CVSS-based lifecycle models.
Define Policy is the foundational step that establishes the program scope, risk tolerance, roles, responsibilities, and remediation timelines that govern all subsequent vulnerability management activities.
Concept tested: Vulnerability management program lifecycle phases
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf
Topics
Community Discussion
No community discussion yet for this question.