Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy
After a successful penetration test, a security consultant provides a client with a report detailing several high-severity vulnerabilities. The client's security team is now tasked with fixing these issues. Which stage of the vulnerability management lifecycle are they primarily engaged in?
- AVulnerability identification
- BVulnerability assessment
- CVulnerability monitoring
- DVulnerability remediation
Show answer & explanationAnswer & explanation
Correct answer: D. Vulnerability remediation
Vulnerability remediation is the process of applying patches, configuration changes, or other fixes to eliminate or reduce identified vulnerabilities. Since the team is 'tasked with fixing these issues,' they are in the remediation phase.
Why the other options are wrong
- A. Identification involves discovering vulnerabilities, which occurred during the penetration test, not when fixing them.
- B. Assessment involves evaluating and prioritizing vulnerabilities, which precedes fixing them.
- C. Monitoring involves continuously watching for new vulnerabilities or changes in risk, which follows remediation.
Vulnerability Remediation
The process of eliminating or mitigating identified vulnerabilities through patching, configuration changes, or other corrective actions.
- Follows vulnerability identification and assessment.
- Involves applying fixes to reduce risk.
- Often includes verifying the fix to ensure effectiveness.
Memory trick: Identify, Assess, Remediate, Verify, Monitor: The circular path to security.