An asset owner reports that a critical CVE on an internet-facing web server has been patched. The SOC analyst needs to confirm the vulnerability no longer exists before closing the remediation ticket. Which action best validates control effectiveness?
Select an answer to reveal the explanation.
Short Explanation
Think of a rescan like checking the lock after you say you fixed it: does the door still open? You need to see the vulnerability disappear from the same scanner output, not just trust the patch note. If you only accept, defer, or add a workaround, you still haven't proved the fix worked.
Full Explanation
Control effectiveness testing in vulnerability management means obtaining evidence that a remediation action actually removed or mitigated the specific weakness. A targeted rescan after patching is the direct verification method because it re-evaluates the same asset against the same scanner content and checks whether the previously detected CVE remains present. This closes the loop between reported remediation and observed risk state. Merely applying compensating controls may reduce exploitability, but it does not prove the original patch or configuration fix succeeded. Marking a vulnerability as accepted changes the organizational risk decision, not the technical remediation status, and can leave the weakness present. Deferring remediation through a compliance exception records a temporary tolerance for risk and does not validate that the asset is now secure. Exam caveat: A scanner result is evidence of detection, not proof of complete business-risk closure, so correlate it with asset owner confirmation and ticketing. Operational check: Rerun the scanner against the exact affected IP or hostname using the same scan policy and compare the CVE or plugin result to the original finding.