CompTIA Cybersecurity Analyst (CySA+)
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
2.1 Given a scenario, implement an information security
vulnerability management process. -
correct answer ✅CompTIA
• Identification of requirements -
correct answer ✅As an organization begins developing a
vulnerability management program, it should first undertake the
identification of any internal or external requirements for
vulnerability scanning. These requirements may come from the
regulatory environment(s) in which the organization operates
and/or internal policy-driven requirements.
Vulnerability Management Programs -
correct answer ✅They seek to identify, prioritize and remediate
vulnerabilities before an attacker exploits them to undermine the
confidentiality, integrity, or availability of enterprise information
assets.
- Regulatory environments -
correct answer ✅an environment in which an organization exists
or operates that is controlled to a significant degree by laws, rules,
or regulations put in place by government (federal, state, or local),
,CompTIA Cybersecurity Analyst (CySA+)
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
industry groups, or other organizations. In a nutshell, it is what
happens when you have to play by someone else's rules, or else risk
serious consequences. A common feature of this is that they have
enforcement groups and procedures to deal with noncompliance.
Examples include, HIPPA, ISO/IEC 27001, PCI DSS and GLBA.
Health Insurance Portability and Accountability Act of 1996 (HIPPA)
-
correct answer ✅United States law enacted in 1996 to provide
data privacy and security provisions for safeguarding medical
information. It does not specifically require that an organization
conduct vulnerability scanning. It establishes penalties (ranging
from $100 to 1.5 million) for covered entities that fail to safeguard
phi.
Gramm-Leach-Bliley Act (GLBA) -
correct answer ✅A law that requires banks and financial
institutions to alert customers of their policies and practices in
disclosing customer information. It does not specifically require
that an organization conduct vulnerability scanning.
,CompTIA Cybersecurity Analyst (CySA+)
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
PCI DSS (Payment Card Industry Data Security Standard) -
correct answer ✅A global standard for protecting stored,
processed, or transmitted payment card information.
ISO/IEC 27001 (The International Organization for
Standardization/International Electrotechnical Commission) -
correct answer ✅Specifies requirements for establishing,
implementing, operating, monitoring, reviewing, maintaining and
improving a documented information security management
system. It is is arguably the most popular voluntary security
standard in the world and covers every important aspect of
developing and maintaining good information security.
Federal Information Security Management Act of 2002 (FISMA) -
correct answer ✅is United States legislation that defines a
comprehensive framework to protect government information,
operations and assets against natural or man-made threats. It
requires that government agencies and other organizations OS's on
behalf of government agencies comply with a series of security
standards.
, CompTIA Cybersecurity Analyst (CySA+)
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
Federal Information Processing Standards (FIPS) -
correct answer ✅a set of standards that describe document
processing, encryption algorithms and other information
technology standards for use within non-military government
agencies and by government contractors and vendors who work
with the agencies.
- Corporate policy -
correct answer ✅is an overall general statement produced by
senior management (or a selected policy board or committee) that
dictates what role security plays within the organization.
Security policy -
correct answer ✅can be organizational, issue specific, or system
specific.
Organizational Security Policy -
correct answer ✅management establishes how a security program
will be set up, lays out the program's goals, assigns responsibilities,
shows the strategic and tactical value of security, and outlines how
enforcement should be carried out.
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
2.1 Given a scenario, implement an information security
vulnerability management process. -
correct answer ✅CompTIA
• Identification of requirements -
correct answer ✅As an organization begins developing a
vulnerability management program, it should first undertake the
identification of any internal or external requirements for
vulnerability scanning. These requirements may come from the
regulatory environment(s) in which the organization operates
and/or internal policy-driven requirements.
Vulnerability Management Programs -
correct answer ✅They seek to identify, prioritize and remediate
vulnerabilities before an attacker exploits them to undermine the
confidentiality, integrity, or availability of enterprise information
assets.
- Regulatory environments -
correct answer ✅an environment in which an organization exists
or operates that is controlled to a significant degree by laws, rules,
or regulations put in place by government (federal, state, or local),
,CompTIA Cybersecurity Analyst (CySA+)
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
industry groups, or other organizations. In a nutshell, it is what
happens when you have to play by someone else's rules, or else risk
serious consequences. A common feature of this is that they have
enforcement groups and procedures to deal with noncompliance.
Examples include, HIPPA, ISO/IEC 27001, PCI DSS and GLBA.
Health Insurance Portability and Accountability Act of 1996 (HIPPA)
-
correct answer ✅United States law enacted in 1996 to provide
data privacy and security provisions for safeguarding medical
information. It does not specifically require that an organization
conduct vulnerability scanning. It establishes penalties (ranging
from $100 to 1.5 million) for covered entities that fail to safeguard
phi.
Gramm-Leach-Bliley Act (GLBA) -
correct answer ✅A law that requires banks and financial
institutions to alert customers of their policies and practices in
disclosing customer information. It does not specifically require
that an organization conduct vulnerability scanning.
,CompTIA Cybersecurity Analyst (CySA+)
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
PCI DSS (Payment Card Industry Data Security Standard) -
correct answer ✅A global standard for protecting stored,
processed, or transmitted payment card information.
ISO/IEC 27001 (The International Organization for
Standardization/International Electrotechnical Commission) -
correct answer ✅Specifies requirements for establishing,
implementing, operating, monitoring, reviewing, maintaining and
improving a documented information security management
system. It is is arguably the most popular voluntary security
standard in the world and covers every important aspect of
developing and maintaining good information security.
Federal Information Security Management Act of 2002 (FISMA) -
correct answer ✅is United States legislation that defines a
comprehensive framework to protect government information,
operations and assets against natural or man-made threats. It
requires that government agencies and other organizations OS's on
behalf of government agencies comply with a series of security
standards.
, CompTIA Cybersecurity Analyst (CySA+)
2.0 Vulnerability Management Exam
Actual Questions and Answers 2026
Federal Information Processing Standards (FIPS) -
correct answer ✅a set of standards that describe document
processing, encryption algorithms and other information
technology standards for use within non-military government
agencies and by government contractors and vendors who work
with the agencies.
- Corporate policy -
correct answer ✅is an overall general statement produced by
senior management (or a selected policy board or committee) that
dictates what role security plays within the organization.
Security policy -
correct answer ✅can be organizational, issue specific, or system
specific.
Organizational Security Policy -
correct answer ✅management establishes how a security program
will be set up, lays out the program's goals, assigns responsibilities,
shows the strategic and tactical value of security, and outlines how
enforcement should be carried out.