Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security team is implementing a vulnerability management program. According to industry best practices, which THREE of the following are essential components of a mature vulnerability management process?

⚠ Common exam trap

A common misconception in vulnerability management is that meeting compliance requirements (e.g., quarterly scans) is sufficient for maturity. However, a mature program requires continuous scanning, remediation SLAs based on severity, and a false positive management process to ensure efficiency and effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False positive management process

Option C (False positive management process) is essential because scanners inevitably generate findings that are not genuine vulnerabilities, and a mature program must triage, validate, and document these to prevent wasted remediation effort and alert fatigue. Option D (Remediation SLAs based on severity) is correct because best practices such as those in NIST SP 800-40 and CIS Controls require risk-based timeframes (for example, critical vulnerabilities remediated in days versus low-severity in weeks) to prioritize limited resources. Option E (Continuous scanning capability) is correct because mature programs move beyond point-in-time assessments to ongoing discovery and monitoring, enabling timely detection of new vulnerabilities and asset changes. Option A (Manual patch management) does not belong because mature programs automate patching and configuration management rather than relying on manual processes, which are error-prone and unscalable. Option B (Quarterly vulnerability scans) does not belong because quarterly scanning alone is insufficient and outdated; mature programs scan continuously or at least much more frequently, and quarterly scans are typically only a compliance minimum, not a best-practice component.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manual patch management

    Why it's wrong here

    Manual patching cannot scale to the estate's patch volume, lacks auditable scheduling and leaves remediation dependent on individual effort, so it fails the repeatability a mature process demands. It is tempting because hands-on patching suits small, static environments with few systems where automation overhead is unjustified.

  • ✗

    Quarterly vulnerability scans

    Why it's wrong here

    Quarterly scanning leaves exposures undetected for up to three months, so remediation cannot keep pace with newly disclosed vulnerabilities; mature programmes scan continuously or at least monthly. It is tempting because quarterly cycles suit low-change environments or compliance regimes specifying only annual or quarterly assessment.

  • ✓

    False positive management process

    Why this is correct

    A false positive management process is essential because it triages scanner findings that incorrectly flag benign activity, preventing analyst fatigue and wasted remediation effort. Without it, genuine vulnerabilities get buried, so the programme cannot mature or prioritise accurately.

  • ✓

    Remediation SLAs based on severity

    Why this is correct

    Remediation SLAs based on severity ensure identified vulnerabilities are fixed within defined, risk-prioritised timeframes. This satisfies the mature-process requirement by closing the loop between detection and verified correction, rather than leaving findings unaddressed after scanning.

  • ✓

    Continuous scanning capability

    Why this is correct

    Continuous scanning keeps asset and vulnerability data current, catching new exposures and configuration drift between periodic assessments. Without it, findings age quickly and remediation prioritisation rests on stale snapshots, undermining the maturity of the vulnerability management programme.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.