- Home
- All questions
- Question 112
CompTIA Security+ study material · question 112 of 611
Where does the vulnerability management lifecycle begin?
Show the answer
Answer: C. With knowing which software and versions the organisation runs, down to packages and libraries
Everything downstream depends on the inventory: an unknown component cannot be matched to an advisory.
Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.2 Software Vulnerability Management Life Cycle