CS0-004 - Vulnerability Management - Section 2.4

Explain concepts related to control types, risks, and vulnerability management.

Explain control types and how they map to vulnerability response and handling, including risk acceptance, avoidance, transfer and mitigation, exceptions and exemptions, and service-level objectives for remediation. Describe the vulnerability management lifecycle and governance concepts such as change control, patch management and validation of remediation.

control types (technical, operational, managerial)risk treatment (accept, avoid, transfer, mitigate)remediation SLOs and exceptionsvulnerability management lifecyclepatch management and validation

Practice question for this objective

Free sampleVulnerability Managementmedium

During a review, an analyst is asked to sort security awareness training, a documented patch policy, and an intrusion detection sensor into control categories. Which statement correctly describes how these map to managerial, operational, and technical control types?

  • AAwareness training is technical, the patch policy is operational, and the IDS sensor is managerial.
  • BThe patch policy is managerial, the awareness training is operational, and the IDS sensor is technical. Correct
  • CAwareness training is managerial, the patch policy is technical, and the IDS sensor is operational.
  • DAll three are operational controls because each one supports the day-to-day vulnerability management programme.
Map controls to managerial, operational, or technical types based on whether they govern, are people-driven, or are system-enforced. Control types describe how a safeguard is enacted: managerial controls are governance and policy, operational controls are carried out by people, and technical controls are enforced by systems, so a policy, training, and a sensor land in three different categories.

Why A is wrong: Tempting because policies feel operational and training feels hands-on, but the categories are swapped: a written policy is managerial and a sensor is technical.

Why B is correct: Correct: policies and governance are managerial, human-executed processes such as training are operational, and system-enforced mechanisms such as an IDS are technical.

Why C is wrong: This mislabels the policy and the sensor; a policy is a managerial document and a sensor is a technical mechanism, so two of the three assignments are wrong.

Why D is wrong: Supporting daily operations does not make every control operational; the category reflects how a control is enacted, and a policy and a sensor clearly fall outside the operational type.

See more CS0-004 practice questions, answers explained.

More in this domain

Back to all Vulnerability Management objectives, or the CS0-004 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.