Which Program Compensates Security Researchers for Vulnerabilities?
A company is expanding its threat surface program and allowing individuals to security test the company’s internet-facing application. The company will compensate researchers based on the vulnerabilities discovered. Which of the following best describes the program the company is setting up?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the ability to distinguish a public, incentive-based vulnerability discovery effort (bug bounty) from formal engagements like penetration testing or red team simulations, where testers are hired for a defined exercise.
A bug bounty program is a crowdsourced security testing initiative where a company pays external researchers for valid vulnerabilities. CompTIA SY0-701 candidates should recognize bug bounty as the correct answer because it directly matches the scenario of compensating outside individuals for vulnerability discoveries.
Choosing penetration testing (D) is a common mistake because it also involves authorized vulnerability testing; however, penetration testing is a structured, contracted engagement with a specific team, not an open program that invites and compensates any researcher.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B is correct because the question explicitly describes a "threat surface program" that allows "individuals" to test the company's internet-facing application and "compensate[s] researchers" based on discovered vulnerabilities. This matches the definition of a bug bounty program, which crowdsources security testing to an open community of external researchers. Commenter [1] accurately points out that "a bug bounty program incentivizes external security researchers to find and report vulnerabilities," while commenter [2] notes that the company is paying non-employees, which is the essence of bug bounty. The consensus among comments is unanimous: B is the right answer.
Why the Other Options Are Wrong
Option A, open-source intelligence, involves gathering publicly available information and does not actively test or exploit an application, so it does not fit the scenario. Option C, red team, is a coordinated adversarial exercise conducted by an in-house or hired team to simulate real-world attacks; it is not an open program that pays independent researchers per vulnerability. Option D, penetration testing, involves authorized, typically contracted testing of systems by designated testers for a specific scope and timeline, but it does not involve opening the program to the public or offering bug-based compensation. Therefore, B is the only option that matches all elements of the question.
Community Comment Notes
The comments overwhelmingly support B, with several users simply writing "B" or explaining why bug bounty is the answer. Commenter [3] highlights that "bug bounty hunters can earn money by discovering zero-day vulnerabilities," reinforcing the financial incentive. Commenter [4] provides a detailed explanation of inviting external researchers and rewarding their findings, which directly aligns with the official question scenario. All votes show B with 100% agreement, so the community has no significant disagreement on this answer.
Official Reference
Exam Strategy
When you see keywords like "individuals," "compensate researchers," and "internet-facing application," immediately think of bug bounty programs. Do not confuse this with penetration testing, which is a formal engagement with a hired tester. Read the question for the presence of an open call to the public and bug-based payment, as those are the defining traits of a bug bounty.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →