Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium
A large organization is implementing a new vulnerability management program. One of the key challenges is ensuring that all discovered vulnerabilities are tracked from identification through remediation and verification. Which component of a vulnerability management system is primarily responsible for maintaining the lifecycle status of vulnerabilities?
- AAsset Inventory
- BTicketing/Workflow Management
- CReporting Engine
- DVulnerability Scanner
Show answer & explanationAnswer & explanation
Correct answer: B. Ticketing/Workflow Management
Ticketing/Workflow Management systems are crucial for tracking the lifecycle of vulnerabilities, assigning responsibilities, managing remediation tasks, and ensuring that vulnerabilities are addressed and verified until closure.
Why the other options are wrong
- A. Asset inventory lists assets and their properties but doesn't track the status of vulnerabilities found on them.
- C. A reporting engine generates reports based on vulnerability data but isn't primarily for tracking individual vulnerability lifecycle status.
- D. A vulnerability scanner identifies vulnerabilities but doesn't manage their lifecycle status.
Vulnerability Workflow Management
The process and tools used to track and manage vulnerabilities from discovery through remediation, verification, and closure.
- Ensures accountability for vulnerability resolution.
- Provides visibility into the status of all identified vulnerabilities.
- Often integrates with IT service management (ITSM) systems.
Memory trick: Scan Assets, Report Findings, Manage Workflow for Remediation.