CompTIA Security+ (SY0-701)Security Program Management and OversightHard

A software company launches a program that invites external security researchers to find and responsibly report vulnerabilities in its public-facing applications in exchange for monetary rewards based on severity. Which term best describes this program?

  1. ARules of engagement
  2. BBug bounty program
  3. CRed team engagement
  4. DVulnerability scan
Show answer & explanation

Correct answer: B. Bug bounty program

A bug bounty program is a crowdsourced initiative where external researchers are financially rewarded for discovering and responsibly disclosing vulnerabilities, typically scaled by severity of the finding.

Why the other options are wrong

  • A. Rules of engagement define scope and boundaries for a pen test, not a standalone reward program.
  • C. A red team engagement involves a contracted, defined team simulating adversaries, not an open crowdsourced program.
  • D. A vulnerability scan is an automated technical process, not a researcher-driven reward program.

Bug Bounty Program

A crowdsourced security initiative that rewards external researchers for discovering and responsibly disclosing vulnerabilities, usually with payouts scaled to severity.

  • Open to a broad pool of independent researchers, unlike contracted pen tests
  • Rewards are typically tiered by vulnerability severity/impact
  • Often managed via platforms with defined scope and disclosure policies

Memory trick: Bounty = pay per bug found, like a reward poster

More Security Program Management and Oversight questions