Courseiva
Vulnerability Management →easyMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is using OpenVAS to perform a vulnerability scan of an internal network. The scan completes and generates a report listing several vulnerabilities. What is the next step in the vulnerability lifecycle?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prioritization

After discovery (scanning), the next step is prioritization of vulnerabilities based on risk, exploitability, and business impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Prioritization

    Why this is correct

    Immediately after scan results are generated, analysts must rank findings by exploitability, asset criticality, and business context so limited remediation resources are directed at the highest-impact vulnerabilities first, which is prioritization.

  • ✗

    Verification

    Why it's wrong here

    Verification confirms whether a reported vulnerability is genuine or already patched, and it occurs after analysis, not directly after the scan. The raw OpenVAS output needs triage first to establish which findings warrant validation. Verification would be correct once candidate vulnerabilities have been identified and require confirmation.

  • ✗

    Reporting

    Why it's wrong here

    Reporting is a communication activity, not the immediate lifecycle step after a scan completes. The findings must first be analysed and validated to separate true positives from false positives. Reporting would be correct when presenting confirmed, prioritised results to management or stakeholders for decision-making.

  • ✗

    Remediation

    Why it's wrong here

    Remediation follows prioritisation and validation, not the raw scan output. The scan has only produced findings; they must first be analysed and confirmed as genuine before fixes are scheduled. Remediation is the later stage where patches or configuration changes are applied to close validated vulnerabilities.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.