Courseiva

CISM Information Security Programme Practice Question

A security manager is designing a vulnerability management program. Which TWO of the following are essential processes?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regular vulnerability scanning of all systems.

Option D is correct because regular vulnerability scanning of all systems is the foundational discovery process of any vulnerability management program — without recurring authenticated and unauthenticated scans (e.g., via tools like Nessus, Qualys, or OpenVAS) you cannot identify, track, or measure the vulnerabilities present in your environment. Option E is correct because risk-based prioritization is essential for remediation: since it is impossible to fix everything at once, vulnerabilities must be ranked by factors such as CVSS score, EPSS probability, asset criticality, and exploit availability so that limited resources address the highest-risk exposures first. Option A is not essential because immediate 24-hour patching of all vulnerabilities is operationally unrealistic and ignores risk context — critical, internet-facing flaws may warrant rapid patching, but low-risk issues do not. Option B is not essential because a vulnerability disclosure program for external researchers is a valuable complement for receiving reports, but it is not a core required process of vulnerability management. Option C is not essential because annual penetration testing of all applications is a point-in-time assurance activity that supplements, but does not replace, continuous vulnerability identification and prioritization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediate patching of all vulnerabilities within 24 hours.

    Why it's wrong here

    Patching every vulnerability within 24 hours ignores risk-based prioritisation, which is the essential process; criticality and exploitability determine remediation timelines. It is tempting because rapid patching reduces exposure, and would be correct for a defined category of critical, actively exploited vulnerabilities rather than all findings.

  • ✗

    Vulnerability disclosure program for external researchers.

    Why it's wrong here

    A disclosure programme handles externally reported vulnerabilities, which is valuable but not one of the two essential processes for an internal vulnerability management programme. It is tempting because coordinated disclosure strengthens remediation, and would be correct for an organisation seeking to manage researcher-reported flaws alongside its own scanning.

  • ✗

    Penetration testing of all applications annually.

    Why it's wrong here

    Annual penetration testing is a point-in-time assessment, not a continuous process for identifying and remediating vulnerabilities across the estate. It is tempting because penetration testing validates exploitability, and would be correct as a periodic assurance activity complementing, rather than replacing, ongoing vulnerability identification and remediation.

  • ✓

    Regular vulnerability scanning of all systems.

    Why this is correct

    Regular scanning discovers assets, missing patches and misconfigurations across the estate, feeding the inventory and findings that every later remediation step depends on. Without this recurring discovery process, the vulnerability management programme cannot identify what to prioritise or fix.

  • ✓

    Risk-based prioritization of vulnerabilities for remediation.

    Why this is correct

    Risk-based prioritisation ranks findings by exploitability, asset criticality and business impact, so remediation effort targets the vulnerabilities posing genuine loss exposure rather than raw CVSS counts. This satisfies the programme's need to allocate finite patching resources where they reduce risk most.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.