SY0-701 exam dumps

SY0-701 practice question 302 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 302

Single answerValidation of remediation: Rescanning , Audit , Verification

A security administrator deployed patches to address a critical web server vulnerability identified during last week's vulnerability scan. Change records show the patches were applied successfully, but the organization must now confirm that the issue is actually resolved before closing the ticket. Which action is the BEST next step to validate remediation?

  1. A

    Review the original scan report and mark the finding as resolved because the patch was approved and deployed

  2. B

    Perform a targeted rescan of the affected web server and verify the vulnerability no longer appears

  3. C

    Wait until the next quarterly audit to determine whether the remediation was effective

  4. D

    Ask the system owner to confirm that the application is working normally and close the finding

Show answer and explanation

Correct answer: B

Explanation

The best answer is to perform a targeted rescan of the affected web server and verify that the vulnerability no longer appears. In Security+ terms, validation of remediation focuses on confirming that a corrective action was effective, not just that it was attempted. Rescanning is the most direct technical method for this because it compares the post-remediation state against the original finding. Audit records, change tickets, and deployment logs are important supporting evidence, but they primarily demonstrate that a process was followed. Verification requires evidence that the vulnerability was actually removed or mitigated. In practice, many organizations use a combination of change documentation, rescanning, and analyst review before formally closing findings. This aligns with common vulnerability management best practices from sources such as NIST guidance on continuous monitoring and remediation validation, where organizations are expected to verify that security deficiencies have been corrected rather than assuming success based solely on implementation records.

  • A. Incorrect.

    This is incorrect because reviewing the original scan report does not validate that remediation was successful. The original report only shows the vulnerability existed at the time of the initial assessment. Patch deployment records are useful for change management and audit purposes, but they do not prove the vulnerability is no longer present.

  • B. Correct.

    This is correct because validation of remediation requires confirming that the control or fix actually removed the identified weakness. A targeted rescan of the affected asset is a standard best practice after remediation. It provides current evidence that the vulnerability is no longer detected and supports verification before closing the ticket.

  • C. Incorrect.

    This is incorrect because an audit can help confirm process compliance and documentation, but waiting for a future audit delays validation and leaves uncertainty about the current security posture. Audits are not a substitute for prompt technical verification after remediation.

  • D. Incorrect.

    This is incorrect because functional testing by the system owner may confirm that the application still works, but normal operation does not prove the vulnerability has been eliminated. This is a common misconception: availability or usability checks are not the same as security verification.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam