Which activities are associated with vulnerability management?

Which of the following activities are associated with vulnerability management? (Choose two.)

  1. Reporting Source Reference Answer
  2. Prioritization Source Reference Answer
  3. Exploiting
  4. Correlation
  5. Containment

Community Votes

AB
100%

100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to distinguish between proactive vulnerability management processes and reactive incident response actions, with the common trap being confusing containment or correlation with standard VM workflows.

This question assesses knowledge of core vulnerability management lifecycle activities, specifically reporting and prioritization. The community overwhelmingly agrees that these two functions are essential for tracking and effectively addressing security weaknesses.

Candidates frequently select Containment (E) because they associate it with limiting damage, but containment belongs to incident response rather than the ongoing vulnerability management cycle. Others might choose Correlation (D), mistaking SIEM log analysis features for direct VM tasks.

Community Discussion (9 comments)

laternak26 👍 6 Selected: AB
A. Reporting: Regularly documenting and reporting on vulnerabilities, including their status, potential risks, and the actions taken to remediate them, is a core part of the vulnerability management process. This helps to track progress and ensure that vulnerabilities are addressed in a timely manner. B. Prioritization: Given that not all vulnerabilities are equally critical, prioritizing them based on factors like the severity of the vulnerability, the risk to the organization, and the potential impact is essential. This helps to allocate resources efficiently and address the most pressing vulnerabilities first NOT E. Containment. Containment is an activity typically associated with incident response or a breach management process. While related to managing security risks, containment is not specifically a part of vulnerability management, which focuses more on identifying, assessing, and mitigating vulnerabilities.
iliecomptia 👍 3 Selected: AB
From the study guide: A: Vulnerability reporting is a crucial aspect of vulnerability management and is critical in maintaining an organization’s cybersecurity posture. (page 247) B: Vulnerability analysis helps prioritize remediation efforts by identifying the most critical vulnerabilities that pose the most significant risk to an organization. Prioritization is typically based on factors such as the severity of the vulnerability, the ease of exploitation, and the potential impact of an attack. Prioritizing vulnerabilities helps an organization focus limited resources on addressing the most significant threats first. (page 245) For those who say D is an answer, in the “Vulnerability Response and Remediation” section of the study guide there is no mention of containment.
Fagann 👍 2 Selected: AB
you would not contain a vulnerability. Containment is for isolating infected devices from the network and it is in incident response process.
4617f0b 👍 1 Selected: BD
Why the other options are not correct according to ChatGPT: A. Reporting: While reporting is important, it is not a core activity of vulnerability management itself but rather an activity associated with tracking and communicating the process. C. Exploiting: Exploiting is not a part of vulnerability management. The goal of vulnerability management is to identify, assess, and mitigate vulnerabilities, not to exploit them. E. Containment: Containment is typically associated with incident response, where you contain the impact of a security breach or attack, not directly with vulnerability management. F. Tabletop exercise: Tabletop exercises are used to practice responses to security incidents, such as breaches or attacks, and are not part of vulnerability management.
AndyK2 👍 2 Selected: AB
The selected activities (reporting and prioritization) are fundamental to effective vulnerability management, helping organizations systematically address potential security weaknesses.
Cocopqr 👍 1 Selected: BE
B. Prioritization and E. Containment Here's a breakdown of why: Prioritization: This involves assessing the severity of vulnerabilities and prioritizing which ones to address first. This ensures that the most critical vulnerabilities are addressed promptly. Containment: This involves isolating or mitigating the impact of a vulnerability to prevent further damage. This might include patching systems, blocking network traffic, or quarantining infected devices. The other options are not directly related to vulnerability management: Reporting: While reporting vulnerabilities is important, it's not a core activity of vulnerability management. Exploiting: This is an action performed by attackers, not vulnerability managers. Correlation: This is related to threat intelligence and incident response, not vulnerability management. Tabletop exercise: These are used for training and planning, but not directly for vulnerability management.
Cloudboy 👍 1
A and B
3b6be6b 👍 1
A. Reporting: Communicating the identified vulnerabilities, their potential impact, and remediation steps to stakeholders. B. Prioritization: Determining which vulnerabilities to address first based on their severity, exploitability, and potential impact on the organization.
jacobtriestech 👍 2
B and E Prioritization: This involves assessing the severity of identified vulnerabilities and ranking them based on factors like potential impact and likelihood of exploitation. It helps organizations focus on the most critical vulnerabilities first. Containment: This refers to actions taken to limit the spread and impact of a vulnerability, especially if it has been exploited. This might involve isolating affected systems, blocking network traffic, or implementing emergency patches.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Vulnerability Management Lifecycle

Vulnerability management is a continuous, cyclical process designed to systematically identify, evaluate, treat, and mitigate security vulnerabilities in software and hardware. According to the CompTIA Security+ SY0-701 objectives, this process relies heavily on structured workflows to ensure resources are allocated efficiently.

Why Reporting and Prioritization Are Correct

Prioritization (B) is a foundational step where identified vulnerabilities are ranked based on severity, exploitability, asset criticality, and business impact. As noted in community discussions, this ensures teams address the highest-risk issues first rather than attempting to fix everything simultaneously. Reporting (A) tracks the status of findings, remediation efforts, and compliance metrics, providing stakeholders with visibility into the organization's security posture. Multiple voters confirmed that both activities are explicitly called out in official study guides as mandatory components of the VM framework.

Why Other Options Are Incorrect

Exploiting (C) is an offensive security activity performed during penetration testing or red team exercises, not a defensive vulnerability management function. Correlation (D) refers to combining data from multiple sources to detect patterns, which is primarily a SIEM (Security Information and Event Management) function rather than a direct VM task. Containment (E) is a reactive measure used to isolate compromised systems during an active breach. As highlighted by several candidates, containment falls squarely under the Incident Response lifecycle, making it a distractor for this specific question.

Exam Takeaway

The vulnerability management workflow prioritizes proactive identification and risk-based triage over reactive containment, making Reporting and Prioritization the definitive answers.

Official Reference

Exam Strategy

When encountering vulnerability management questions, focus on the proactive lifecycle stages: scan, assess, prioritize, remediate, and report. Actively filter out reactive incident response terms like containment, eradication, or lessons learned, as these belong to a different operational phase.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide