An analyst finds a critical vulnerability in a production server. The scanner report and change ticket exist, but management asks for evidence that the finding is being handled under the organization's risk process. Which artifact best demonstrates governed vulnerability response?
Select an answer to reveal the explanation.
Short Explanation
Think of a risk register like your vulnerability to-do list with names and deadlines. It shows the finding, who owns it, and how it's being treated. Without that owner and plan, you're just collecting scanner output.
Full Explanation
Governed vulnerability response requires more than identifying a weakness; it requires a documented risk decision. A risk register is the control artifact that records each accepted or managed finding, the responsible owner, the chosen treatment, and the target date. This creates accountability and allows auditors or managers to confirm the organization consciously handled the risk rather than merely detecting it. A scanner report, while essential for discovery, only shows technical evidence such as CVE, port, and severity, and it does not assign ownership or indicate whether the organization will remediate, mitigate, transfer, or accept the issue. An executive dashboard can reveal trends, aging, or exception volume, but it is a management view and does not normally capture the per-finding treatment rationale required for governed response. A change ticket records the operational work of applying a patch or configuration change, yet it focuses on implementation and approvals, not on the underlying risk decision or the named risk owner. Exam caveat: when the question emphasizes governance, accountability, or treatment planning, select the artifact that links a vulnerability to an owner and an approved response. Operational check: sample a risk register entry and confirm it contains the CVE or finding ID, affected asset, risk owner, treatment decision, due date, and review cadence.