Due to new regulations, a company has decided to institute an organizational vulnerability management program and assign the function to the security team. Which of the following frameworks would BEST support the program? (Choose two.)
Scored a 880 on this exam and had this question. The correct answer is ISO 27000 and NIST. ITIL is a framework for IT Service Management. Nothing to do with vulnerabilities.
NIST Special Publications (e.g., NIST SP 800-40) offer comprehensive guidance on vulnerability management.
ISO 27001 outlines how to build and maintain an Information Security Management System (ISMS), which includes vulnerability management.
It's definitely not A or E, so that leaves B, C & D. NIST is definitely a right answer, but I have doubts between ISO and ITIL... .
https://advisera.com/27001academy/blog/2016/03/07/iso-27001-vs-itil-similarities-and-differences
This should be NIST and ISO 27000 series. See ISO 27001 control A.12.6.1 for managing vulnerabilities which is focused on Timely identification of vulnerabilities, Assessment of organization’s exposure to a vulnerability, Proper measures considering the associated risks.
Agree with Dan, OWASP is focused on web apps, not an entire security framework.
upvoted 6 times
...
This section is not available anymore. Please use the main Exam Page.CS0-001 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
danierug
Highly Voted 5 years, 8 months agomd3v
Highly Voted 4 years, 7 months ago4ee1800
Most Recent 3 weeks, 5 days agoBlind_Hatred
4 years, 10 months agos3curity1
4 years, 10 months agoashleypride
5 years, 1 month agolupinart
4 years, 11 months agojai_fagundes
4 years, 8 months agoKonrad007
5 years, 1 month agoKC
5 years, 2 months ago