CISSP Security Operations Practice Question
During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?
⚠ Common exam trap
CISSP often tests the ordering of the vulnerability management lifecycle, tempting candidates to pick 'verification' or 'reporting' because those feel like quality steps, when the lifecycle's next action after prioritization is remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remediation
The vulnerability management lifecycle is typically: identify → prioritize (assess/rank) → remediate → verify → report, with risk acceptance as an alternative outcome to remediation. After vulnerabilities are identified and prioritized, the next action is to remediate (patch, mitigate, or compensate), because prioritization exists to drive remediation decisions. Verification and reporting come after remediation to confirm the fix and communicate status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verification
Why it's wrong here
Verification is a crucial step that follows the actual implementation of fixes. Its purpose is to confirm that the applied remediation measures have effectively eliminated or mitigated the identified vulnerabilities and have not introduced new issues. Therefore, verification cannot be the immediate next step after prioritization, as there must first be something to verify, which is the remediation itself.
- ✗
Reporting
Why it's wrong here
While reporting is an essential component of the vulnerability management lifecycle, it typically occurs after remediation and subsequent verification. Initial reports might highlight identified vulnerabilities and their prioritization, but comprehensive reporting on the status of resolution and the effectiveness of controls is performed once remediation actions have been completed and confirmed. It is not the direct operational step immediately following prioritization.
- ✓
Remediation
Why this is correct
Following the identification and prioritization of vulnerabilities based on their potential impact and likelihood, the immediate and most critical next phase in the vulnerability management lifecycle is remediation. This involves applying patches, reconfiguring systems, implementing compensating controls, or otherwise eliminating or reducing the risk posed by the identified weaknesses. Prioritization dictates what to fix first, and remediation is how those fixes are applied.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is a deliberate management decision to acknowledge a risk and take no action to reduce its likelihood or impact, often due to the cost of remediation outweighing the potential harm, or if the risk falls within an organization's acceptable threshold. While it is a valid risk response strategy, it is an alternative to remediation, not a subsequent step in the process of actively fixing vulnerabilities after they have been prioritized for action.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.