After the library district patches a critical web server CVE, management asks how the team will prove the fix worked. Which validation activity is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Closing the ticket is not the same as proving the bolt is tight—run the scanner again (or an equivalent check) and see the finding go away. Validation means evidence, not hope or a marketing note.
Full Explanation
Validation after remediation typically includes rescanning, configuration verification, or audit evidence that the vulnerability is remediated. Assuming success from ticket closure alone leaves residual risk if the patch failed or was incomplete. Skipping verification to avoid new findings defeats the purpose of vulnerability management feedback loops.