712-50 Question 350
Single answerDevelop vulnerability management systemsA newly appointed CISO is redesigning the enterprise vulnerability management program after a board review found that patching metrics looked strong, yet several internet-facing systems remained exposed to high-risk weaknesses for months. The organization has a hybrid environment, limited remediation resources, and different asset owners across business units. The CISO wants a system that improves actual risk reduction rather than simply increasing the number of vulnerabilities closed. Which action would be the MOST effective first step when developing the vulnerability management system?
- A
Establish a risk-based vulnerability management process that integrates asset criticality, exposure, exploitability, and compensating controls into remediation prioritization and reporting
- B
Mandate that all critical and high vulnerabilities be remediated within the same enterprise-wide SLA regardless of asset type or business context
- C
Increase the frequency of authenticated scans from monthly to weekly and report the total number of findings to the board each quarter
- D
Outsource patch deployment to the infrastructure team and measure success primarily by overall patch compliance percentages
Show answer and explanation
Correct answer: A
Explanation
The best answer is to first establish a risk-based vulnerability management process. In executive practice, vulnerability management is not simply scanning plus patching; it is a governance-driven capability that includes asset inventory, vulnerability discovery, contextual prioritization, remediation workflows, exception handling, metrics, and accountability. Best practices from NIST's vulnerability management guidance, NIST SP 800-40 on enterprise patch management planning, and common industry approaches such as risk-based vulnerability management emphasize that organizations should consider asset criticality, exposure, threat intelligence, exploit availability, and business impact when prioritizing action. Frameworks such as the CIS Critical Security Controls also support inventory-driven and risk-informed remediation rather than volume-based reporting. For a CISO, the key is to design the system so scarce resources are applied where they reduce organizational risk the most, and so executive reporting reflects real exposure reduction rather than operational activity alone.
- A. Correct.
Correct. A mature vulnerability management system should prioritize remediation based on business and technical risk, not raw scanner severity alone. Integrating asset criticality, internet exposure, known exploitation, exploit maturity, and compensating controls helps direct scarce remediation resources to the weaknesses most likely to cause material impact. This directly addresses the scenario where patching metrics appear favorable but important exposures remain unresolved. For a CISO, designing governance, prioritization criteria, ownership, exception handling, and meaningful reporting is the foundational step.
- B. Incorrect.
Incorrect. A uniform SLA for all critical and high vulnerabilities may appear disciplined, but it ignores asset value, threat context, operational constraints, and compensating controls. In practice, a public-facing payment system with active exploitation risk should not necessarily be treated the same as an isolated internal test server. This approach often drives superficial compliance behavior and can divert resources away from the highest-risk exposures.
- C. Incorrect.
Incorrect. More frequent scanning can improve visibility, but visibility alone does not solve prioritization and governance weaknesses. Reporting only total findings to the board is also a poor executive metric because it emphasizes volume rather than risk reduction, exposure reduction, or time to remediate on critical assets. This option addresses symptoms, not the core design flaw in the program.
- D. Incorrect.
Incorrect. Patch compliance is only one component of vulnerability management and does not account for configuration issues, unsupported software, compensating controls, exception management, exposure, or exploitability. Delegating patching to infrastructure teams without first establishing a risk-based governance model and prioritization framework would likely preserve the same gap identified by the board.