Study. uk . com
  1. Home
  2. All questions
  3. Question 112

CompTIA Security+ study material · question 112 of 611

Where does the vulnerability management lifecycle begin?

  1. With a scheduled authenticated scan
  2. With agreeing the maintenance window
  3. With knowing which software and versions the organisation runs, down to packages and libraries
  4. With subscribing to a threat intelligence feed
Show the answer

Answer: C. With knowing which software and versions the organisation runs, down to packages and libraries

Everything downstream depends on the inventory: an unknown component cannot be matched to an advisory.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.2 Software Vulnerability Management Life Cycle

Challenge yourself on this topic → Study as cards