ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your company hosts its web application on Amazon EC2. A recent Amazon Inspector scan completed the discovery phase and produced a list of medium- and high-severity findings. Following the vulnerability management lifecycle, the security team needs to move to the next phase before any changes are made to the instances. Which action BEST represents the prioritization/analysis phase?
Run a new Amazon Inspector assessment to confirm that previously reported vulnerabilities no longer appear.
Apply the latest operating-system and application patches to all EC2 instances with AWS Systems Manager Patch Manager.
Use the CVSS scores from Amazon Inspector to rank findings and align them with business criticality to build a remediation backlog.
Document any remaining vulnerabilities and route a residual-risk acceptance memo to executive leadership for approval.
The prioritization/analysis phase focuses on ranking discovered vulnerabilities so that remediation work can target the most important issues first. Using the CVSS-based severities provided by Amazon Inspector and mapping each finding to the business importance of the affected workload produces a risk-based backlog that guides subsequent remediation. Immediately patching, rescanning, or formally accepting residual risk occur in later lifecycle phases-remediation, verification/reassessment, and reporting or risk acceptance respectively.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CVSS in vulnerability assessment?
Open an interactive chat with Bash
How does Amazon Inspector integrate with vulnerability management?
Open an interactive chat with Bash
What are the main phases of a vulnerability management lifecycle?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .