Topic 16 Practice Test 1 covers Vulnerability Management for CompTIA Security+ SY0-701 and maps to objective 4.3: Explain various activities associated with vulnerability management. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
An architect working on a vulnerability-management program review needs one capability that provides commercial or private threat intelligence supplied by a vendor or specialized provider and another that provides standardized identifier assigned to a publicly disclosed vulnerability. Which TWO selections are the best match? Choose TWO.
- Proprietary threat feed
- Compensating control
- Bug bounty program
- CVE
- Information-sharing organization
Correct Answers: A, D
Correct Answers
Answer A is correct because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider. It belongs in the fixed-count answer set because it covers one of the stated requirements. Information-sharing organization instead serves an industry or community group that shares security intelligence among members and cannot replace this function.
Answer D is correct because CVE means a standardized identifier assigned to a publicly disclosed vulnerability. The fixed-count item needs this function in the answer set. Information-sharing organization covers an industry or community group that shares security intelligence among members, a different requirement.
Incorrect Answers
Answer B is incorrect because Compensating control means an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. The scenario calls for CVE, Proprietary threat feed. Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports. The question requires exactly 2 selections: CVE, Proprietary threat feed. This option falls outside that required set. For example, Proprietary threat feed is required for commercial or private threat intelligence supplied by a vendor or specialized provider.
Answer E is incorrect because Information-sharing organization means an industry or community group that shares security intelligence among members. The scenario calls for CVE, Proprietary threat feed. Selecting this option would leave one of those required functions uncovered. For example, CVE is required for a standardized identifier assigned to a publicly disclosed vulnerability.
Question 2
To improve collective awareness of threats affecting similar organizations, which security approach should be selected?
- Static application analysis
- Dark-web monitoring
- Information-sharing organization
- Exposure factor
Correct Answer: C
Correct Answer
Answer C is correct because Information-sharing organization means an industry or community group that shares security intelligence among members. The requirement maps directly to this function, whereas Dark-web monitoring is aimed at observation of hidden or criminal online sources for leaked credentials, data, or threat activity.
Incorrect Answers
Answer A is incorrect because Static application analysis refers to inspection of application code or binaries without executing them. That concept can be valid in another scenario, but this question is testing an industry or community group that shares security intelligence among members; Information-sharing organization therefore fits the requirement more directly.
Answer B is incorrect because Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity. The question is not asking for this function. It is testing an industry or community group that shares security intelligence among members, so Information-sharing organization is the stronger fit.
Answer D is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. The key mismatch is functional: Information-sharing organization addresses an industry or community group that shares security intelligence among members, the need stated by the question.
Question 3
During a vulnerability-management program review, the team has two independent requirements: (1) industry or community group that shares security intelligence among members; and (2) ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. Which TWO choices best satisfy those requirements? Choose TWO.
- Rescanning
- Proprietary threat feed
- Responsible disclosure program
- Risk-based prioritization
- Information-sharing organization
Correct Answers: D, E
Correct Answers
Answer D is correct because Risk-based prioritization means ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. This option satisfies a specific requirement in the stem; Rescanning serves performing another assessment after remediation and therefore is not interchangeable with it.
Answer E is correct because Information-sharing organization means an industry or community group that shares security intelligence among members. The fixed-count item needs this function in the answer set. Proprietary threat feed covers commercial or private threat intelligence supplied by a vendor or specialized provider, a different requirement.
Incorrect Answers
Answer A is incorrect because Rescanning means performing another assessment after remediation. The scenario calls for Information-sharing organization, Risk-based prioritization. Selecting this option would leave one of those required functions uncovered. For example, Risk-based prioritization is required for ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context.
Answer B is incorrect because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider. The fixed-count answer set is Information-sharing organization, Risk-based prioritization; this option does not fill one of those named functions.
Answer C is incorrect because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely. The scenario calls for Information-sharing organization, Risk-based prioritization. Selecting this option would leave one of those required functions uncovered.
Question 4
Two requirements remain open in a vulnerability-management program review: observation of hidden or criminal online sources for leaked credentials, data, or threat activity; defined process for external researchers to report security vulnerabilities safely. Which TWO options close those specific gaps? Choose TWO.
- Risk-based prioritization
- Dark-web monitoring
- Responsible disclosure program
- Exposure factor
- False positive
Correct Answers: B, C
Correct Answers
Answer B is correct because Dark-web monitoring means observation of hidden or criminal online sources for leaked credentials, data, or threat activity. The fixed-count item needs this function in the answer set. False positive covers a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context, a different requirement.
Answer C is correct because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely. The fixed-count item needs this function in the answer set. Risk-based prioritization covers ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context, a different requirement.
Incorrect Answers
Answer A is incorrect because Risk-based prioritization means ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. The question requires exactly 2 selections: Dark-web monitoring, Responsible disclosure program. This option falls outside that required set. For example, Responsible disclosure program is required for a defined process for external researchers to report security vulnerabilities safely.
Answer D is incorrect because Exposure factor means the estimated percentage of asset value lost if a specific risk event occurs. The required choices are Dark-web monitoring, Responsible disclosure program. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because False positive means a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. The required choices are Dark-web monitoring, Responsible disclosure program. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 5
Which term describes inspection of application code or binaries without executing them?
- Static application analysis
- Vulnerability scanning
- CVSS
- Proprietary threat feed
Correct Answer: A
Correct Answer
Answer A is correct because Static application analysis means inspection of application code or binaries without executing them. This matches the requirement as written. CVSS can be valid in another context, but it is used for a standardized scoring framework for describing vulnerability severity characteristics.
Incorrect Answers
Answer B is incorrect because Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems. The key mismatch is functional: Static application analysis addresses inspection of application code or binaries without executing them, the need stated by the question.
Answer C is incorrect because CVSS refers to a standardized scoring framework for describing vulnerability severity characteristics. The concept is valid, but it does not match this stem. The required function is inspection of application code or binaries without executing them, which maps to Static application analysis.
Answer D is incorrect because Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider. The question is not asking for this function. It is testing inspection of application code or binaries without executing them, so Static application analysis is the stronger fit.
Question 6
Which term describes observation of hidden or criminal online sources for leaked credentials, data, or threat activity?
- False positive
- Dark-web monitoring
- Responsible disclosure program
- Vulnerability scanning
Correct Answer: B
Correct Answer
Answer B is correct because Dark-web monitoring means observation of hidden or criminal online sources for leaked credentials, data, or threat activity. The requirement maps directly to this function, whereas Responsible disclosure program is aimed at a defined process for external researchers to report security vulnerabilities safely.
Incorrect Answers
Answer A is incorrect because False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. That concept can be valid in another scenario, but this question is testing observation of hidden or criminal online sources for leaked credentials, data, or threat activity; Dark-web monitoring therefore fits the requirement more directly.
Answer C is incorrect because Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely. The concept is valid, but it does not match this stem. The required function is observation of hidden or criminal online sources for leaked credentials, data, or threat activity, which maps to Dark-web monitoring.
Answer D is incorrect because Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems. The question is not asking for this function. It is testing observation of hidden or criminal online sources for leaked credentials, data, or threat activity, so Dark-web monitoring is the stronger fit.
Question 7
To quantify impact in risk analysis and prioritization, which security approach should be selected?
- Exposure factor
- Vulnerability scanning
- Proprietary threat feed
- False negative
Correct Answer: A
Correct Answer
Answer A is correct because Exposure factor means the estimated percentage of asset value lost if a specific risk event occurs. This is the precise fit for the scenario. Proprietary threat feed serves the different purpose of commercial or private threat intelligence supplied by a vendor or specialized provider.
Incorrect Answers
Answer B is incorrect because Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems. That concept can be valid in another scenario, but this question is testing the estimated percentage of asset value lost if a specific risk event occurs; Exposure factor therefore fits the requirement more directly.
Answer C is incorrect because Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider. The key mismatch is functional: Exposure factor addresses the estimated percentage of asset value lost if a specific risk event occurs, the need stated by the question.
Answer D is incorrect because False negative refers to a real vulnerability that an assessment fails to detect. The scenario instead requires the estimated percentage of asset value lost if a specific risk event occurs, which is why Exposure factor is the better answer; this option serves the different function defined above.
Question 8
Which term describes formally approved deviation from a security requirement under defined conditions and ownership?
- Exception or exemption
- Bug bounty program
- False positive
- Responsible disclosure program
Correct Answer: A
Correct Answer
Answer A is correct because Exception or exemption means formally approved deviation from a security requirement under defined conditions and ownership. That is the function the question is testing. False positive would instead be used for a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context.
Incorrect Answers
Answer B is incorrect because Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports. The scenario instead requires formally approved deviation from a security requirement under defined conditions and ownership, which is why Exception or exemption is the better answer; this option serves the different function defined above.
Answer C is incorrect because False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. The scenario instead requires formally approved deviation from a security requirement under defined conditions and ownership, which is why Exception or exemption is the better answer; this option serves the different function defined above.
Answer D is incorrect because Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely. This could be appropriate elsewhere, but the required function is formally approved deviation from a security requirement under defined conditions and ownership; that makes Exception or exemption the precise choice.
Question 9
Which term describes tracking libraries and dependencies for known vulnerabilities and risky versions?
- Static application analysis
- Package monitoring
- False positive
- Proprietary threat feed
Correct Answer: B
Correct Answer
Answer B is correct because Package monitoring means tracking libraries and dependencies for known vulnerabilities and risky versions. The requirement maps directly to this function, whereas Static application analysis is aimed at inspection of application code or binaries without executing them.
Incorrect Answers
Answer A is incorrect because Static application analysis refers to inspection of application code or binaries without executing them. That concept can be valid in another scenario, but this question is testing tracking libraries and dependencies for known vulnerabilities and risky versions; Package monitoring therefore fits the requirement more directly.
Answer C is incorrect because False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. This could be appropriate elsewhere, but the required function is tracking libraries and dependencies for known vulnerabilities and risky versions; that makes Package monitoring the precise choice.
Answer D is incorrect because Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider. This could be appropriate elsewhere, but the required function is tracking libraries and dependencies for known vulnerabilities and risky versions; that makes Package monitoring the precise choice.
Question 10
Two requirements remain open in a vulnerability-management program review: observation of hidden or criminal online sources for leaked credentials, data, or threat activity; responsible disclosure program that offers rewards for qualifying vulnerability reports. Which TWO options close those specific gaps? Choose TWO.
- Information-sharing organization
- Bug bounty program
- Dark-web monitoring
- Proprietary threat feed
- Vulnerability scanning
Correct Answers: B, C
Correct Answers
Answer B is correct because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports. One required function is exactly what this option provides. Vulnerability scanning may be useful elsewhere, but it is used for automated probing and assessment used to identify known weaknesses and configuration problems.
Answer C is correct because Dark-web monitoring means observation of hidden or criminal online sources for leaked credentials, data, or threat activity. It belongs in the fixed-count answer set because it covers one of the stated requirements. Information-sharing organization instead serves an industry or community group that shares security intelligence among members and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Information-sharing organization means an industry or community group that shares security intelligence among members. The scenario calls for Bug bounty program, Dark-web monitoring. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Proprietary threat feed means commercial or private threat intelligence supplied by a vendor or specialized provider. Every answer slot must map to a stated requirement. The correct set is Bug bounty program, Dark-web monitoring, so this option cannot replace one of those selections.
Answer E is incorrect because Vulnerability scanning means automated probing and assessment used to identify known weaknesses and configuration problems. The required choices are Bug bounty program, Dark-web monitoring. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 11
What is a defined process for external researchers to report security vulnerabilities safely?
- CVE
- Vulnerability scanning
- Exposure factor
- Responsible disclosure program
Correct Answer: D
Correct Answer
Answer D is correct because Responsible disclosure program means a defined process for external researchers to report security vulnerabilities safely. That makes it the best answer here; Vulnerability scanning addresses automated probing and assessment used to identify known weaknesses and configuration problems, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because CVE refers to a standardized identifier assigned to a publicly disclosed vulnerability. The question is not asking for this function. It is testing a defined process for external researchers to report security vulnerabilities safely, so Responsible disclosure program is the stronger fit.
Answer B is incorrect because Vulnerability scanning refers to automated probing and assessment used to identify known weaknesses and configuration problems. The concept is valid, but it does not match this stem. The required function is a defined process for external researchers to report security vulnerabilities safely, which maps to Responsible disclosure program.
Answer C is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. The key mismatch is functional: Responsible disclosure program addresses a defined process for external researchers to report security vulnerabilities safely, the need stated by the question.
Question 12
Which reported vulnerability or alert appears valid to the tool but is not actually present or exploitable in the assessed context?
- Risk-based prioritization
- Dynamic application analysis
- Penetration testing
- False positive
Correct Answer: D
Correct Answer
Answer D is correct because False positive means a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. This matches the requirement as written. Penetration testing can be valid in another context, but it is used for authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused.
Incorrect Answers
Answer A is incorrect because Risk-based prioritization refers to ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. That concept can be valid in another scenario, but this question is testing a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context; False positive therefore fits the requirement more directly.
Answer B is incorrect because Dynamic application analysis refers to testing an application while it is running to observe behavior and identify exploitable conditions. The scenario instead requires a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context, which is why False positive is the better answer; this option serves the different function defined above.
Answer C is incorrect because Penetration testing refers to authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused. The concept is valid, but it does not match this stem. The required function is a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context, which maps to False positive.
Question 13
Which industry or community group shares security intelligence among members?
- Bug bounty program
- False negative
- Information-sharing organization
- Rescanning
Correct Answer: C
Correct Answer
Answer C is correct because Information-sharing organization means an industry or community group that shares security intelligence among members. The requirement maps directly to this function, whereas Bug bounty program is aimed at a responsible disclosure program that offers rewards for qualifying vulnerability reports.
Incorrect Answers
Answer A is incorrect because Bug bounty program refers to a responsible disclosure program that offers rewards for qualifying vulnerability reports. The scenario instead requires an industry or community group that shares security intelligence among members, which is why Information-sharing organization is the better answer; this option serves the different function defined above.
Answer B is incorrect because False negative refers to a real vulnerability that an assessment fails to detect. The concept is valid, but it does not match this stem. The required function is an industry or community group that shares security intelligence among members, which maps to Information-sharing organization.
Answer D is incorrect because Rescanning refers to performing another assessment after remediation. The key mismatch is functional: Information-sharing organization addresses an industry or community group that shares security intelligence among members, the need stated by the question.
Question 14
Which real vulnerability an assessment fails to detect?
- Risk-based prioritization
- Open-source intelligence (OSINT)
- False negative
- CVSS
Correct Answer: C
Correct Answer
Answer C is correct because False negative means a real vulnerability that an assessment fails to detect. That makes it the best answer here; CVSS addresses a standardized scoring framework for describing vulnerability severity characteristics, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Risk-based prioritization refers to ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. The key mismatch is functional: False negative addresses a real vulnerability that an assessment fails to detect, the need stated by the question.
Answer B is incorrect because Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity. The key mismatch is functional: False negative addresses a real vulnerability that an assessment fails to detect, the need stated by the question.
Answer D is incorrect because CVSS refers to a standardized scoring framework for describing vulnerability severity characteristics. This could be appropriate elsewhere, but the required function is a real vulnerability that an assessment fails to detect; that makes False negative the precise choice.
Question 15
Which term describes authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused?
- Risk-based prioritization
- Penetration testing
- Compensating control
- Open-source intelligence (OSINT)
Correct Answer: B
Correct Answer
Answer B is correct because Penetration testing means authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused. That is the function the question is testing. Open-source intelligence (OSINT) would instead be used for publicly available information used to identify threats, exposures, or attacker activity.
Incorrect Answers
Answer A is incorrect because Risk-based prioritization refers to ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. The concept is valid, but it does not match this stem. The required function is authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused, which maps to Penetration testing.
Answer C is incorrect because Compensating control refers to an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. The question is not asking for this function. It is testing authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused, so Penetration testing is the stronger fit.
Answer D is incorrect because Open-source intelligence (OSINT) refers to publicly available information used to identify threats, exposures, or attacker activity. This could be appropriate elsewhere, but the required function is authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused; that makes Penetration testing the precise choice.
Question 16
To support consistent severity assessment while still considering local business context, which security approach should be selected?
- False positive
- Exposure factor
- CVSS
- Information-sharing organization
Correct Answer: C
Correct Answer
Answer C is correct because CVSS means a standardized scoring framework for describing vulnerability severity characteristics. The deciding point is functional fit: this option covers the stated need, while Information-sharing organization addresses an industry or community group that shares security intelligence among members.
Incorrect Answers
Answer A is incorrect because False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. This could be appropriate elsewhere, but the required function is a standardized scoring framework for describing vulnerability severity characteristics; that makes CVSS the precise choice.
Answer B is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. The key mismatch is functional: CVSS addresses a standardized scoring framework for describing vulnerability severity characteristics, the need stated by the question.
Answer D is incorrect because Information-sharing organization refers to an industry or community group that shares security intelligence among members. The key mismatch is functional: CVSS addresses a standardized scoring framework for describing vulnerability severity characteristics, the need stated by the question.
Question 17
Reviewers working through a vulnerability-management program review identify three separate needs: publicly available information used to identify threats, exposures, or attacker activity; authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused; responsible disclosure program that offers rewards for qualifying vulnerability reports. Which THREE choices map to those needs? Choose THREE.
- Open-source intelligence (OSINT)
- Static application analysis
- Compensating control
- Rescanning
- Penetration testing
- Bug bounty program
Correct Answers: A, E, F
Correct Answers
Answer A is correct because Open-source intelligence (OSINT) means publicly available information used to identify threats, exposures, or attacker activity. This selection maps directly to one of the named needs. Rescanning addresses performing another assessment after remediation, so it does not satisfy the same slot.
Answer E is correct because Penetration testing means authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused. This selection maps directly to one of the named needs. Rescanning addresses performing another assessment after remediation, so it does not satisfy the same slot.
Answer F is correct because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports. One required function is exactly what this option provides. Static application analysis may be useful elsewhere, but it is used for inspection of application code or binaries without executing them.
Incorrect Answers
Answer B is incorrect because Static application analysis means inspection of application code or binaries without executing them. The scenario calls for Penetration testing, Open-source intelligence (OSINT), Bug bounty program. Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Compensating control means an alternate safeguard that reduces risk when the direct remediation cannot be implemented immediately. The fixed-count answer set is Penetration testing, Open-source intelligence (OSINT), Bug bounty program; this option does not fill one of those named functions.
Answer D is incorrect because Rescanning means performing another assessment after remediation. The question requires exactly 3 selections: Penetration testing, Open-source intelligence (OSINT), Bug bounty program. This option falls outside that required set. For example, Penetration testing is required for authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused.
Question 18
To validate real-world impact beyond a scanner finding, which security approach should be selected?
- False positive
- Penetration testing
- Responsible disclosure program
- Exposure factor
Correct Answer: B
Correct Answer
Answer B is correct because Penetration testing means authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused. This matches the requirement as written. Responsible disclosure program can be valid in another context, but it is used for a defined process for external researchers to report security vulnerabilities safely.
Incorrect Answers
Answer A is incorrect because False positive refers to a reported vulnerability or alert that appears valid to the tool but is not actually present or exploitable in the assessed context. The key mismatch is functional: Penetration testing addresses authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused, the need stated by the question.
Answer C is incorrect because Responsible disclosure program refers to a defined process for external researchers to report security vulnerabilities safely. The question is not asking for this function. It is testing authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused, so Penetration testing is the stronger fit.
Answer D is incorrect because Exposure factor refers to the estimated percentage of asset value lost if a specific risk event occurs. That concept can be valid in another scenario, but this question is testing authorized exploitation-oriented testing used to demonstrate how weaknesses can be combined and abused; Penetration testing therefore fits the requirement more directly.
Question 19
Which standardized identifier is assigned to a publicly disclosed vulnerability?
- Proprietary threat feed
- Exception or exemption
- Dark-web monitoring
- CVE
Correct Answer: D
Correct Answer
Answer D is correct because CVE means a standardized identifier assigned to a publicly disclosed vulnerability. That is the function the question is testing. Proprietary threat feed would instead be used for commercial or private threat intelligence supplied by a vendor or specialized provider.
Incorrect Answers
Answer A is incorrect because Proprietary threat feed refers to commercial or private threat intelligence supplied by a vendor or specialized provider. That concept can be valid in another scenario, but this question is testing a standardized identifier assigned to a publicly disclosed vulnerability; CVE therefore fits the requirement more directly.
Answer B is incorrect because Exception or exemption refers to formally approved deviation from a security requirement under defined conditions and ownership. This could be appropriate elsewhere, but the required function is a standardized identifier assigned to a publicly disclosed vulnerability; that makes CVE the precise choice.
Answer C is incorrect because Dark-web monitoring refers to observation of hidden or criminal online sources for leaked credentials, data, or threat activity. The scenario instead requires a standardized identifier assigned to a publicly disclosed vulnerability, which is why CVE is the better answer; this option serves the different function defined above.
Question 20
Two requirements remain open in a vulnerability-management program review: responsible disclosure program that offers rewards for qualifying vulnerability reports; performing another assessment after remediation. In practical terms, it is used to verify that a vulnerability was actually removed and did not remain exposed. Which TWO options close those specific gaps? Choose TWO.
- Information-sharing organization
- Risk-based prioritization
- Rescanning
- Bug bounty program
- False negative
Correct Answers: C, D
Correct Answers
Answer C is correct because Rescanning means performing another assessment after remediation. It belongs in the fixed-count answer set because it covers one of the stated requirements. False negative instead serves a real vulnerability that an assessment fails to detect and cannot replace this function.
Answer D is correct because Bug bounty program means a responsible disclosure program that offers rewards for qualifying vulnerability reports. One required function is exactly what this option provides. Information-sharing organization may be useful elsewhere, but it is used for an industry or community group that shares security intelligence among members.
Incorrect Answers
Answer A is incorrect because Information-sharing organization means an industry or community group that shares security intelligence among members. The scenario calls for Rescanning, Bug bounty program. Selecting this option would leave one of those required functions uncovered. For example, Rescanning is required for performing another assessment after remediation.
Answer B is incorrect because Risk-based prioritization means ranking vulnerabilities using severity, exploitability, exposure, business importance, and organizational context. The scenario calls for Rescanning, Bug bounty program. Selecting this option would leave one of those required functions uncovered. For example, Rescanning is required for performing another assessment after remediation.
Answer E is incorrect because False negative means a real vulnerability that an assessment fails to detect. Every answer slot must map to a stated requirement. The correct set is Rescanning, Bug bounty program, so this option cannot replace one of those selections.