Vulnerability Management, Monitoring and Alerting
This topic focuses on scanning, prioritization, remediation, compensating controls, SIEM alerts, threat hunting, and operational monitoring.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Vulnerability management is a lifecycle: identify, prioritize, remediate, verify, and report.
Exam cue: Prioritize internet-exposed critical assets with known exploitation.
Concept 2
Risk-based prioritization considers exploitability, exposure, asset criticality, business impact, and compensating controls.
Exam cue: Verify remediation after patching or configuration changes.
Concept 3
Monitoring and alerting require tuning, enrichment, escalation, and review to reduce noise and preserve signal.
Exam cue: Tune alerts based on false positives and missed detections.
Risk pitfalls and guardrails
Ranking solely by CVSS without asset context.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Closing findings before rescanning or validating.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Ignoring alert fatigue and escalation procedures.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Vulnerability Scan
A vulnerability scan identifies known weaknesses, missing patches, and risky configurations.
Credentialed Scan
A credentialed scan has authenticated access and usually finds deeper host-level issues.
Penetration Test
A penetration test actively attempts exploitation to demonstrate impact and paths.
CVSS
CVSS provides a standardized severity score but does not replace business risk context.
Risk-Based Prioritization
Risk-based prioritization combines severity, exploitability, exposure, and asset value.
Remediation
Remediation removes or fixes the weakness that creates risk.
Compensating Control
A compensating control reduces risk when the preferred control cannot be implemented.
SIEM
A SIEM collects, correlates, and alerts on security events from multiple sources.
Alert Tuning
Alert tuning adjusts logic or thresholds to improve detection value.
Threat Hunting
Threat hunting proactively searches for suspicious activity that existing alerts may miss.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A scanner identifies missing patches and weak services without attempting to exploit them. What assessment is being performed?
An unauthenticated scan finds only open ports, while an authenticated scan identifies missing local patches and weak registry settings. Why?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
