Which troubleshooting step would be appropriate if a SOC discovers that a critical vulnerability identified by container scanning several weeks ago was never actually remediated, despite the scanning tool correctly flagging it?
Correct Answer: Review the remediation workflow's tracking and assignment process to determine why the flagged finding did not result in a completed fix, and identify whether the gap is in ticket creation, assignment, prioritization, or verification
Explanation: Reviewing the remediation workflow's tracking/assignment process to find the gap (ticketing, assignment, prioritization, or verification) is the appropriate diagnostic step, unlike blaming desktop wallpaper, disabling scanning entirely, wrongly assuming this is deprecated, blaming unrelated air conditioning, or blaming the phase of the moon.
Correct Answer: Review the remediation workflow's tracking and assignment process to determine why the flagged finding did not result in a completed fix, and identify whether the gap is in ticket creation, assignment, prioritization, or verification
Explanation: Reviewing the remediation workflow's tracking/assignment process to find the gap (ticketing, assignment, prioritization, or verification) is the appropriate diagnostic step, unlike blaming desktop wallpaper, disabling scanning entirely, wrongly assuming this is deprecated, blaming unrelated air conditioning, or blaming the phase of the moon.