Study. uk . com
  1. Home
  2. All questions
  3. Question 600

CompTIA Security+ study material · question 600 of 611

What does the reporting step of the vulnerability management cycle achieve?

  1. It tells owners and management the current exposure, which sustains funding for the work
  2. It assigns CVSS environmental scores
  3. It confirms the remediation worked
  4. It closes the change management ticket
Show the answer

Answer: A. It tells owners and management the current exposure, which sustains funding for the work

Validation confirms the fix; reporting is what keeps the programme visible to the people who resource it.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 3.6 Choose Actionable Enterprise-Level Patching Metrics

Challenge yourself on this topic → Study as cards