Study. uk . com
  1. Home
  2. All questions
  3. Question 174

CompTIA Security+ study material · question 174 of 611

Which step confirms that a deployed patch actually removed the vulnerability?

  1. Recording the change in the ticket system
  2. Rescanning the affected host
  3. Updating the software bill of materials
  4. Reviewing the vendor's release notes
Show the answer

Answer: B. Rescanning the affected host

A patch recorded as deployed but never verified is an assumption rather than a closed finding.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.3 Risk Response Execution

Challenge yourself on this topic → Study as cards