CompTIA Security+ (SY0-701)Security Program Management and OversightHard
A software company launches a program that invites external security researchers to find and responsibly report vulnerabilities in its public-facing applications in exchange for monetary rewards based on severity. Which term best describes this program?
- ARules of engagement
- BBug bounty program
- CRed team engagement
- DVulnerability scan
Show answer & explanationAnswer & explanation
Correct answer: B. Bug bounty program
A bug bounty program is a crowdsourced initiative where external researchers are financially rewarded for discovering and responsibly disclosing vulnerabilities, typically scaled by severity of the finding.
Why the other options are wrong
- A. Rules of engagement define scope and boundaries for a pen test, not a standalone reward program.
- C. A red team engagement involves a contracted, defined team simulating adversaries, not an open crowdsourced program.
- D. A vulnerability scan is an automated technical process, not a researcher-driven reward program.
Bug Bounty Program
A crowdsourced security initiative that rewards external researchers for discovering and responsibly disclosing vulnerabilities, usually with payouts scaled to severity.
- Open to a broad pool of independent researchers, unlike contracted pen tests
- Rewards are typically tiered by vulnerability severity/impact
- Often managed via platforms with defined scope and disclosure policies
Memory trick: Bounty = pay per bug found, like a reward poster