A triage queue contains findings from a network scanner, cloud CSPM, and container scanner. Before remediation work starts, what should the analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of a triage queue like a hospital intake desk: someone has to be tagged as responsible before treatment starts. If you jump straight to patching or escalation without ownership and status, you lose track of who is acting and what stage the finding is in. That is why you assign an owner and set the ticket status first.
Full Explanation
The correct action is to establish accountability and lifecycle state before remediation. In vulnerability management, findings from different scanners are not automatically incidents; they are work items that require an owner, due date, and status so that remediation, exception, or risk acceptance can be tracked. Assigning ownership prevents findings from bouncing between platform teams, while setting status prevents duplicate or stale work. A finding can later be escalated to incident response if active compromise indicators exist, but escalation is not the default first step for scanner findings. Applying compensating controls may be appropriate when patching is delayed, but it should follow ownership and risk triage, not replace accountability. Closing duplicates is useful after deduplication and source validation, yet it must not bypass assigning responsibility for the consolidated finding. Exam caveat: prioritize process order over technical severity when the question asks what must happen before remediation begins. Operational check: confirm each queued finding has a named owner, current status, source, due date, and remediation plan before work starts.