SY0-701 · Question #27
A security practitioner completes a vulnerability assessment on a company's network and finds several vulnerabilities, which the operations team remediates. Which of the following should be done next?
The correct answer is C. Rescan the network. After vulnerabilities are remediated, rescanning the network confirms the fixes actually worked and no new vulnerabilities were introduced - this closes the loop on the remediation cycle before moving on. Why the distractors are wrong: A (Audit): An audit is a broader…
Question
A security practitioner completes a vulnerability assessment on a company's network and finds several vulnerabilities, which the operations team remediates. Which of the following should be done next?
Options
- AConduct an audit.
- BInitiate a penetration test.
- CRescan the network.
- DSubmit a report.
How the community answered
(20 responses)- A10% (2)
- B5% (1)
- C85% (17)
Explanation
After vulnerabilities are remediated, rescanning the network confirms the fixes actually worked and no new vulnerabilities were introduced - this closes the loop on the remediation cycle before moving on.
Why the distractors are wrong:
- A (Audit): An audit is a broader compliance/governance activity, not the immediate next step after patching specific vulnerabilities.
- B (Penetration test): A pentest simulates attacks and is typically scoped separately; it's premature before you've even verified the patches held.
- D (Submit a report): Reporting comes after you've validated the remediations - you don't finalize a report on unverified fixes.
Memory tip: Think of it as a cycle - Find → Fix → Verify → Report. Rescanning is the "Verify" step. You never report before you verify.
Community Discussion
No community discussion yet for this question.