Objective 2.5CS0-003

2.5 Explain concepts related to vulnerability response, handling, and management.

Objective 2.5 sits in Vulnerability Management, which carries 30% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-5Vulnerability ManagementModerate

A security team wants threat modeling to catch design flaws at the cheapest point. When should it first happen?

During the SDLC design phaseCorrect · your answerCorrect: threat modeling starts in design and evolves with the system.
After the first production incidentAn incident is the expensive way to discover a design flaw.
At annual audit timeAudits verify controls; they arrive long after design choices harden.
Once the code freeze landsBy code freeze the architecture is set and changes cost the most.

Correct.

Concept

The earlier a flaw is found, the less has been built on top of it. Security examined at design time gets built in; security examined afterward gets bolted on around what already shipped.

Why A

The cheat sheet says threat modeling is ideally performed early in the SDLC, such as during the design phase, and is then maintained and refined alongside the system rather than done once.

#threat-modeling#sdlc#vulnerability-response

Now you: objective 2.5 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-5Vulnerability ManagementEasy

An analyst introducing threat modeling is asked what its first framing question is, per the Threat Modeling Manifesto. What is it?

Sample question 2 of 3

2-5Vulnerability ManagementModerate

A team modeling a payment system's components, trust boundaries, and data movement wants a visual method. Which technique does the cheat sheet call the most common?

Sample question 3 of 3

2-5Vulnerability ManagementModerate

A team wants a mnemonic that groups threats into six categories, each violating a security attribute, to drive identification. Which technique fits?

Full CySA+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Vulnerability Management