Which Program Compensates Security Researchers for Vulnerabilities?

A company is expanding its threat surface program and allowing individuals to security test the company’s internet-facing application. The company will compensate researchers based on the vulnerabilities discovered. Which of the following best describes the program the company is setting up?

  1. Open-source intelligence
  2. Bug bounty Source Reference Answer
  3. Red team
  4. Penetration testing

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the ability to distinguish a public, incentive-based vulnerability discovery effort (bug bounty) from formal engagements like penetration testing or red team simulations, where testers are hired for a defined exercise.

A bug bounty program is a crowdsourced security testing initiative where a company pays external researchers for valid vulnerabilities. CompTIA SY0-701 candidates should recognize bug bounty as the correct answer because it directly matches the scenario of compensating outside individuals for vulnerability discoveries.

Choosing penetration testing (D) is a common mistake because it also involves authorized vulnerability testing; however, penetration testing is a structured, contracted engagement with a specific team, not an open program that invites and compensates any researcher.

Community Discussion (5 comments)

gollum9 👍 1 Selected: B
B. Bug bounty
dbrowndiver 👍 1 Selected: B
The scenario describes a program where the company invites external individuals, often called ethical hackers or researchers, to find vulnerabilities in its application and offers compensation based on the discoveries. Bug bounty programs are initiatives where organizations invite external researchers to test their software or systems for vulnerabilities. Researchers are rewarded with financial compensation, recognition, or both, based on the severity and impact of the vulnerabilities they find.
Etc_Shadow28000 👍 4 Selected: B
B. Bug bounty A bug bounty program incentivizes external security researchers to find and report vulnerabilities in a company's applications or systems. Researchers are compensated based on the severity and impact of the vulnerabilities they uncover, helping the company to improve its security posture by leveraging a wide range of expertise.
Jimmy1017 👍 4 Selected: B
B bug bounty because they’re paying non employees to find vulnerabilities.
Abcd123321 👍 3 Selected: B
Bug bounty hunters can earn money by discovering zero-day vulnerabilities

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is correct because the question explicitly describes a "threat surface program" that allows "individuals" to test the company's internet-facing application and "compensate[s] researchers" based on discovered vulnerabilities. This matches the definition of a bug bounty program, which crowdsources security testing to an open community of external researchers. Commenter [1] accurately points out that "a bug bounty program incentivizes external security researchers to find and report vulnerabilities," while commenter [2] notes that the company is paying non-employees, which is the essence of bug bounty. The consensus among comments is unanimous: B is the right answer.

Why the Other Options Are Wrong

Option A, open-source intelligence, involves gathering publicly available information and does not actively test or exploit an application, so it does not fit the scenario. Option C, red team, is a coordinated adversarial exercise conducted by an in-house or hired team to simulate real-world attacks; it is not an open program that pays independent researchers per vulnerability. Option D, penetration testing, involves authorized, typically contracted testing of systems by designated testers for a specific scope and timeline, but it does not involve opening the program to the public or offering bug-based compensation. Therefore, B is the only option that matches all elements of the question.

Community Comment Notes

The comments overwhelmingly support B, with several users simply writing "B" or explaining why bug bounty is the answer. Commenter [3] highlights that "bug bounty hunters can earn money by discovering zero-day vulnerabilities," reinforcing the financial incentive. Commenter [4] provides a detailed explanation of inviting external researchers and rewarding their findings, which directly aligns with the official question scenario. All votes show B with 100% agreement, so the community has no significant disagreement on this answer.

Official Reference

Exam Strategy

When you see keywords like "individuals," "compensate researchers," and "internet-facing application," immediately think of bug bounty programs. Do not confuse this with penetration testing, which is a formal engagement with a hired tester. Read the question for the presence of an open call to the public and bug-based payment, as those are the defining traits of a bug bounty.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide