Study. uk . com
  1. Home
  2. All questions
  3. Question 113

CompTIA Security+ study material · question 113 of 611

A team installs a patch and immediately closes the finding. Which lifecycle step have they skipped?

  1. Identifying the vulnerability
  2. Verifying the risk response
  3. Planning the risk response
  4. Preparing the risk response
Show the answer

Answer: B. Verifying the risk response

Verification confirms the fix actually took effect. A patch recorded as deployed but never checked is an assumption.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 §§ 2.2–2.3

Challenge yourself on this topic → Study as cards