Which of the following should a security team use to document persistent vulnerabilities with related recommendations?
Choose an answer
Tap an option to check your answer.
Correct answer: Risk register.
Why this is the answer
A risk register is the appropriate tool for documenting persistent vulnerabilities and their associated recommendations. It provides a centralized, dynamic record of identified risks, their potential impact, likelihood, and the planned mitigation strategies, including recommendations for remediation. This allows for ongoing tracking and management of security posture. An audit report summarizes findings from a formal review, often a snapshot in time, rather than a living document for persistent issues. A compliance report assesses adherence to specific regulations or standards, not a general vulnerability tracking tool. A penetration test is an activity to find vulnerabilities, not a document for managing them over time.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed