Vulnerability Prioritization Tools
A vulnerability scan returned the following results: 2 Critical 5 High 15 Medium 98 Low Which of the following would the information security team most likely use to decide if all discovered vulnerabilities must be addressed and the order in which they should be addressed?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between tools (matrix) and documents/attitudes (register/appetite). The trap is confusing the storage of risks with the prioritization method.
The question asks for the tool used to prioritize vulnerabilities based on scan results. A risk matrix is the correct instrument for mapping impact and likelihood to determine remediation order.
Selecting Risk Register, which stores data but does not inherently perform the prioritization logic or ranking required by the question.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A risk matrix (also known as a risk heat map) is the standard tool used to visualize and prioritize risks by plotting them against dimensions like Impact and Likelihood. Given the specific counts of Critical, High, Medium, and Low vulnerabilities, the team uses the matrix to calculate the overall risk score for each item, thereby deciding the remediation priority.Why the Other Options Are Wrong
Risk appetite defines the organization's tolerance for risk but does not help prioritize specific items. A risk register is a repository for recording identified risks, not a decision-making tool for ordering them. Risk acceptance is a treatment strategy where a risk is acknowledged but not addressed, which contradicts the goal of addressing all vulnerabilities.Community Comment Notes
The community consensus strongly favors the Risk Matrix. As salah112 noted, it helps "decide which vulnerabilities should be addressed first." Another user, Hs1208, simply confirms it is part of Risk Assessment. Maggie22 highlights that it helps organizations "determine how vulnerabilities are addressed" based on calculated levels.Exam Strategy
When asked about 'prioritizing' or 'ordering' risks, look for visual tools like matrices or heat maps. If asked about 'recording' or 'tracking', look for registers or logs.
Frequently Asked Questions
What is the difference between a risk register and a risk matrix?
A risk register is a document that lists all identified risks. A risk matrix is a tool used to analyze and prioritize those risks based on impact and probability.
Does a risk matrix replace a vulnerability scanner?
No. The scanner provides the raw data (vulnerabilities), while the matrix helps the security team interpret that data to decide which ones to fix first.