CISSP Security Operations Practice Question
During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remediation
Remediation (patching or mitigating) follows prioritization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verification
Why it's wrong here
Verification is a crucial step that follows the actual implementation of fixes. Its purpose is to confirm that the applied remediation measures have effectively eliminated or mitigated the identified vulnerabilities and have not introduced new issues. Therefore, verification cannot be the immediate next step after prioritization, as there must first be something to verify, which is the remediation itself.
- ✗
Reporting
Why it's wrong here
While reporting is an essential component of the vulnerability management lifecycle, it typically occurs after remediation and subsequent verification. Initial reports might highlight identified vulnerabilities and their prioritization, but comprehensive reporting on the status of resolution and the effectiveness of controls is performed once remediation actions have been completed and confirmed. It is not the direct operational step immediately following prioritization.
- ✓
Remediation
Why this is correct
Following the identification and prioritization of vulnerabilities based on their potential impact and likelihood, the immediate and most critical next phase in the vulnerability management lifecycle is remediation. This involves applying patches, reconfiguring systems, implementing compensating controls, or otherwise eliminating or reducing the risk posed by the identified weaknesses. Prioritization dictates what to fix first, and remediation is how those fixes are applied.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is a deliberate management decision to acknowledge a risk and take no action to reduce its likelihood or impact, often due to the cost of remediation outweighing the potential harm, or if the risk falls within an organization's acceptable threshold. While it is a valid risk response strategy, it is an alternative to remediation, not a subsequent step in the process of actively fixing vulnerabilities after they have been prioritized for action.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.