Objective 4.3SY0-701

4.3 Explain various activities associated with vulnerability management

Objective 4.3 sits in Security Operations, which carries 28% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Security OperationsEasy

A researcher discovers a flaw and immediately publishes full technical details and working exploit code online, before the vendor has released a patch. Which disclosure model does this describe?

Correct.

The concept

Vulnerability disclosure models describe how and when details of a discovered flaw are made public relative to a vendor's fix.

Why this answer

Publishing complete details and exploit code immediately, without waiting for a patch, matches the full disclosure model.

  • APrivate disclosure keeps details known only to the organization, with publication (if any) at the vendor's discretion.
  • BResponsible disclosure delays publication until a patch exists, unlike this immediate release.
  • This is the correct option: full disclosure releases everything right away.
  • DAnonymous disclosure describes hiding the reporter's identity, not the timing of publication.
Read the sourceOWASP Vulnerability Disclosure Cheat Sheet
Verified against cheatsheetseries.owasp.org · 2026-07-27
vulnerability managementdisclosurereporting

Now you: objective 4.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Security OperationsHard

A security architect needs one capability that continuously checks cloud resource configurations against a security policy, and a separate capability that actively defends running virtual machines and containers from live threats. Which pairing is correct?

Sample question 2 of 3

Security OperationsModerate

After a vendor deploys a fix for a reported flaw, the developers ask the original researcher to confirm the issue no longer reproduces. Performing this recheck corresponds to which vulnerability management activity?

Sample question 3 of 3

Security OperationsHard

A researcher privately reported a flaw and set a 90-day deadline for a patch, following a Project Zero style policy. The vendor misses the deadline with no patch released. What does the disclosure model call for next?

That’s 3 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Operations