SY0-701 exam dumps

SY0-701 practice question 303 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 303

Single answerValidation of remediation: Rescanning , Audit , Verification

After applying emergency patches to several internet-facing Linux web servers to remediate a critical vulnerability identified during a recent vulnerability scan, a security analyst must validate that the remediation was successful before closing the ticket. Which action BEST demonstrates proper validation of remediation?

  1. A

    Run a targeted rescan of the affected servers and verify the vulnerability no longer appears in the scan results

  2. B

    Close the finding after the system administrator confirms the patches were installed successfully

  3. C

    Wait until the next quarterly audit to determine whether the remediation was effective

  4. D

    Review the original vulnerability report to confirm the issue was documented and risk-ranked correctly

Show answer and explanation

Correct answer: A

Explanation

The best answer is to perform a targeted rescan of the remediated systems and verify that the vulnerability no longer appears. In Security+ terms, validation of remediation means confirming that corrective actions were effective, not just implemented. Rescanning is a primary method because it provides technical evidence that the previously identified weakness is no longer detectable. Verification can also include checking patch levels, configuration states, or manual testing where appropriate, but the most direct answer here is a targeted rescan. Audits serve a different purpose: they assess adherence to policies, procedures, and control requirements, often on a periodic basis, and are not the immediate mechanism for validating a single remediation event. Best practices from vulnerability management programs and common guidance such as NIST vulnerability management processes emphasize remediation followed by verification or rescanning before closure of findings.

  • A. Correct.

    Correct. Validation of remediation requires confirming that the vulnerability is no longer present after the fix is applied. A targeted rescan of the affected assets is the most direct and appropriate way to verify that the patch or configuration change actually resolved the issue. This is a standard post-remediation practice in vulnerability management workflows.

  • B. Incorrect.

    Incorrect. Administrator confirmation is helpful as supporting evidence, but it is not sufficient by itself to validate remediation. A patch may fail, be applied incorrectly, or not fully resolve the finding. Security teams should independently verify the result rather than relying only on attestation.

  • C. Incorrect.

    Incorrect. An audit may later confirm process compliance or control effectiveness, but waiting for a scheduled audit does not provide timely verification that the specific vulnerability was remediated. Validation should occur immediately after remediation, not months later.

  • D. Incorrect.

    Incorrect. Reviewing the original report helps with documentation and understanding scope, but it does not confirm that the environment is now secure. Validation of remediation focuses on confirming the issue has been fixed, typically through rescanning, testing, or other technical verification.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam