Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A large organization is implementing a new vulnerability management program. One of the key challenges is ensuring that all discovered vulnerabilities are tracked from identification through remediation and verification. Which component of a vulnerability management system is primarily responsible for maintaining the lifecycle status of vulnerabilities?

  1. AAsset Inventory
  2. BTicketing/Workflow Management
  3. CReporting Engine
  4. DVulnerability Scanner
Show answer & explanation

Correct answer: B. Ticketing/Workflow Management

Ticketing/Workflow Management systems are crucial for tracking the lifecycle of vulnerabilities, assigning responsibilities, managing remediation tasks, and ensuring that vulnerabilities are addressed and verified until closure.

Why the other options are wrong

  • A. Asset inventory lists assets and their properties but doesn't track the status of vulnerabilities found on them.
  • C. A reporting engine generates reports based on vulnerability data but isn't primarily for tracking individual vulnerability lifecycle status.
  • D. A vulnerability scanner identifies vulnerabilities but doesn't manage their lifecycle status.

Vulnerability Workflow Management

The process and tools used to track and manage vulnerabilities from discovery through remediation, verification, and closure.

  • Ensures accountability for vulnerability resolution.
  • Provides visibility into the status of all identified vulnerabilities.
  • Often integrates with IT service management (ITSM) systems.

Memory trick: Scan Assets, Report Findings, Manage Workflow for Remediation.

More Vulnerability Management questions