
CompTIA Security+ Education & Occupational Skills Learning Path • Module 5
Risk and Vulnerability Management
Apply identifying weaknesses, evaluating risk, and selecting treatment through approved procedures, objective verification, documentation, and escalation.
Enter your participant information to start activity tracking.
Learning outcomes
- Explain the purpose of identifying weaknesses, evaluating risk, and selecting treatment.
- Apply approved procedures to a realistic CompTIA Security+ situation.
- Verify results, document objective evidence, and escalate conditions outside authorized scope.
Apply the approved workflow
Distinguish a weakness from the threat that could exploit it. Evaluate likelihood, impact, existing controls, and business context. Reliable performance begins with correct identification, current instructions, safe conditions, and a clear understanding of authority.
Key points
- Distinguish a weakness from the threat that could exploit it.
- Evaluate likelihood, impact, existing controls, and business context.
- Confirm scope and prerequisites before acting.
Verify, document, and communicate
Track treatment decisions, owners, due dates, and accepted residual risk. A task is not complete until the result is checked against the expected outcome and the record allows another authorized person to understand what occurred.
Key points
- Track treatment decisions, owners, due dates, and accepted residual risk.
- Record objective facts, actions, results, and unresolved risks.
- Escalate exceptions promptly through the authorized channel.
Applied scenario
Risk and Vulnerability Management: verify before proceeding
During a security operations task involving a protected organizational asset, a CompTIA Security+ practitioner is completing the Risk and Vulnerability Management module scenario. An identifier, instruction, measurement, or expected result does not agree with the available record. The task has a deadline, but proceeding without resolving the conflict could create safety, privacy, quality, compliance, or service risk. Decide how the task should continue and what evidence must be recorded.
← Return to CompTIA Security+ Education & Occupational Skills Learning Path