Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

CISSP Security Operations Practice Question

During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remediation

Remediation (patching or mitigating) follows prioritization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verification

    Why it's wrong here

    Verification is a crucial step that follows the actual implementation of fixes. Its purpose is to confirm that the applied remediation measures have effectively eliminated or mitigated the identified vulnerabilities and have not introduced new issues. Therefore, verification cannot be the immediate next step after prioritization, as there must first be something to verify, which is the remediation itself.

  • Reporting

    Why it's wrong here

    While reporting is an essential component of the vulnerability management lifecycle, it typically occurs after remediation and subsequent verification. Initial reports might highlight identified vulnerabilities and their prioritization, but comprehensive reporting on the status of resolution and the effectiveness of controls is performed once remediation actions have been completed and confirmed. It is not the direct operational step immediately following prioritization.

  • Remediation

    Why this is correct

    Following the identification and prioritization of vulnerabilities based on their potential impact and likelihood, the immediate and most critical next phase in the vulnerability management lifecycle is remediation. This involves applying patches, reconfiguring systems, implementing compensating controls, or otherwise eliminating or reducing the risk posed by the identified weaknesses. Prioritization dictates what to fix first, and remediation is how those fixes are applied.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance is a deliberate management decision to acknowledge a risk and take no action to reduce its likelihood or impact, often due to the cost of remediation outweighing the potential harm, or if the risk falls within an organization's acceptable threshold. While it is a valid risk response strategy, it is an alternative to remediation, not a subsequent step in the process of actively fixing vulnerabilities after they have been prioritized for action.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.