Courseiva

CISM Information Security Programme Practice Question

Which TWO of the following are components of a typical vulnerability management program?

⚠ Common exam trap

CISM often tests the distinction between vulnerability management (proactive identification and remediation of weaknesses) and other security functions like awareness training, monitoring, or penetration testing, causing candidates to select adjacent activities that are not core components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remediating identified vulnerabilities through patching

A vulnerability management program is built around a continuous cycle of discovering, prioritizing, and fixing weaknesses, so option E (conducting regular vulnerability scans) is correct because recurring authenticated and unauthenticated scans are the primary discovery mechanism that populates the vulnerability inventory. Option B (remediating identified vulnerabilities through patching) is correct because remediation—applying vendor patches, configuration changes, or compensating controls—closes the loop and is the ultimate goal of the program; scanning without remediation provides no risk reduction. Option A (security awareness training) belongs to a security education/awareness program, not vulnerability management, since it targets human behavior rather than technical weaknesses. Option C (monitoring network traffic for anomalies) is a detection/incident-monitoring activity typically handled by IDS/IPS, SIEM, or SOC operations, not vulnerability management. Option D (performing penetration tests) is an offensive security assessment that can validate and supplement a vulnerability management program, but it is a point-in-time testing exercise rather than a core component of the ongoing scan-and-remediate process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conducting security awareness training

    Why it's wrong here

    Security awareness training educates users to reduce human error; it does not identify, classify or remediate technical weaknesses in assets. It belongs to a security education programme, whereas vulnerability management covers discovery, prioritisation and remediation of flaws.

  • ✓

    Remediating identified vulnerabilities through patching

    Why this is correct

    Patching directly satisfies the remediation phase of the vulnerability management lifecycle, converting identified weaknesses into resolved risk. A typical programme requires this corrective action alongside discovery and assessment; without remediation, scanning yields no risk reduction. It therefore constitutes a core component, matching the stem's requirement for programme elements.

  • ✗

    Monitoring network traffic for anomalies

    Why it's wrong here

    Traffic anomaly monitoring detects active intrusions or unusual behaviour in real time, which is incident detection rather than systematic discovery and remediation of known weaknesses. It fits network security monitoring or SIEM operations, not vulnerability management.

  • ✗

    Performing penetration tests

    Why it's wrong here

    Penetration tests simulate real-world attacks to validate exploitability, but they are a point-in-time assurance activity, not the continuous identification, prioritisation and remediation cycle that vulnerability management requires. They are tempting because they uncover exploitable weaknesses, and would be the right choice when assessing defensive controls or validating whether existing vulnerabilities can actually be exploited.

  • ✓

    Conducting regular vulnerability scans

    Why this is correct

    Conducting regular vulnerability scans is a core component of a vulnerability management programme because scanning discovers and inventories weaknesses across assets, feeding the identification phase. This satisfies the stem's requirement for programme components, distinguishing discovery activity from subsequent prioritisation, remediation and verification steps.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.