What should be done after remediating vulnerabilities in a network?
A security practitioner completes a vulnerability assessment on a company’s network and finds several vulnerabilities, which the operations team remediates. Which of the following should be done next?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the vulnerability management lifecycle sequence — the trap is confusing an audit (process verification) with a rescan (technical verification of remediation effectiveness).
After vulnerability remediation, rescanning the network is the critical next step to verify fixes and detect any newly introduced issues. Community consensus strongly supports rescanning as the immediate post-remediation action in the vulnerability management lifecycle.
Many candidates choose A (Conduct an audit) because audits verify compliance and remediation, but an audit is a higher-level process check that typically follows a successful rescan, not a replacement for technical validation.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Rescanning the network (Option C) is the immediate next step after remediation to technically validate that patches and fixes were applied correctly and did not introduce new vulnerabilities. This aligns with the standard vulnerability management lifecycle: identify → remediate → verify (rescan) → report. Community comment [1] emphasizes that rescanning confirms remediation effectiveness before proceeding to audits or penetration tests. Comment [5] reinforces that rescanning ensures no new vulnerabilities emerged from the remediation efforts themselves.Why the Other Options Are Wrong
Option A (Conduct an audit) is a common distractor — audits verify policy compliance and process adherence, but they do not technically validate whether specific vulnerabilities were patched. Option B (Initiate a penetration test) is premature; pen tests are broader, more resource-intensive assessments that should only occur after rescans confirm the environment is stable. Option D (Submit a report) is a final step in the lifecycle, but reporting should only happen after rescans validate remediation — reporting unverified results would be premature and potentially misleading.Community Comment Notes
The community is overwhelmingly aligned on C (100% of votes). Comment [3] initially suggested A based on Professor Messer notes mentioning audits for checking remediated systems, but the consensus clarifies that rescanning is the technical verification step that must precede any audit. Comment [4] correctly notes the sequence: rescan first, then audit if needed. The strong consensus (100% votes for C) reflects a clear understanding of the vulnerability management workflow.Official Reference
Exam Strategy
Memorize the vulnerability management lifecycle order: Identify → Classify → Remediate → Rescan (verify) → Report → Audit. When a question asks what to do 'next' after remediation, always look for the technical verification step (rescan) before process-level actions like audits or reporting.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →