certslothcertsloth
SY0-701/Topic 05

CompTIA / Foundational

Hardening and Vulnerability Management

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Inventory, prioritize, fix, verify.

Must remember

You cannot secure unknown assets. Maintain ownership, location, purpose, classification, versions and support status. Apply secure baselines: remove unused software/services, disable default accounts, restrict administration, patch, configure logging and enforce appropriate endpoint protection.

Mobile management can enforce encryption, screen lock, application policy and remote wipe. BYOD raises ownership/privacy boundaries; choose whole-device management versus application/container controls deliberately. Rooted/jailbroken devices weaken assumptions. Wireless, browser, email and document settings can expose different attack surfaces.

Vulnerability scanning identifies potential weaknesses; penetration testing attempts to demonstrate exploitability within authorization and rules of engagement. Credentialed scans can inspect more internal configuration. SAST examines code without running the application; DAST tests running behavior; software composition analysis identifies dependencies and known component issues.

Prioritize using exploitability, exposure, asset value, business impact and active exploitation, not severity alone. CVE identifies a known vulnerability; CVSS scores technical severity; threat intelligence adds context. A low-scoring flaw on a critical exposed identity system can deserve urgent action.

Remediation may mean patching, reconfiguration, removing a component or applying an approved compensating control. Exceptions need owners, expiration and risk acceptance. Test compatibility, maintain a rollback plan, deploy in controlled stages and rescan to verify the issue is resolved. Suppressing an alert is not remediation.

False positive: a reported issue that is not actually present. False negative: an existing issue missed by the test. Confirm with evidence before tuning detection. Sandboxing isolates suspicious code for analysis; a safe analysis environment should not have production access or usable production credentials.

Choose under exam pressure

Requirement Choice and reason
Find missing updates at scale Authenticated scanning with appropriate permissions.
Prove a finding’s impact Authorized validation or penetration testing within scope.
Cannot immediately patch Time-bound approved mitigation and tracked risk.

Traps

  • CVSS alone is not business risk.
  • An uncredentialed scan may miss issues visible from inside the system.

Active recall

1. Scan or penetration test to inventory suspected flaws?

A vulnerability scan; penetration testing validates selected attack paths.

2. What follows remediation?

Verification/rescanning and documented closure or remaining risk.

3. What is a false negative?

A real issue that the test failed to detect.

4. Why track EOL assets?

Unsupported systems may no longer receive fixes and require replacement or compensating controls.

5. What must a patch exception include?

An accountable owner, risk decision, mitigation and review/expiry plan.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.