Missiora
Vulnerability Management

Technology Fundamentals

Vulnerability Management

1 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

You can't fix what you can't see. Vulnerability management is the continuous process of finding and reducing weaknesses before attackers exploit them.

Interactive explainer

Vulnerability Management

The continuous cycle of finding and fixing weaknesses.

11. Identify22. Assess & prioritise33. Remediate44. Verify & report

Tap or hover a part to learn more.

1. Identify

Inventory & scan.

Know your assets, then scan them regularly (authenticated and unauthenticated) to discover vulnerabilities. You can't fix what you can't see.

Check your understanding

1. What does a CVSS score describe?

2. How does a vulnerability scan differ from a pen test?

Practise this in AI Interview™

The lifecycle

  • Identify — asset inventory and regular scanning (authenticated and unauthenticated).
  • Assess & prioritiseCVEs describe known flaws; CVSS scores severity, but true priority weighs exploitability, exposure and business impact.
  • Remediate — patch, configure or apply compensating controls; verify with a re-scan.
  • Report — track metrics and trends over time.

Distinct from a penetration test (a point-in-time simulated attack). Patching connects to Malware & Endpoint Security and Security+.

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

Prioritising and remediating vulnerabilities is core blue-team and engineering work.

Technical questions
How do you prioritise which vulnerabilities to fix first?+

Combine CVSS with exploitability, internet exposure and business impact — not severity alone.

Behavioural questions
Tell me about driving remediation across teams.+

Show communicating risk clearly, agreeing timelines and verifying fixes.

Real-world scenarios
“A scan returns hundreds of findings.”+

Expected answer: Triage by real risk (exposure + exploitability + impact), fix the critical exposed ones first, and re-scan to verify.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
SOC AnalystSecurity EngineerVulnerability Analyst
Skills you're proving
ScanningCVSS/CVERemediation
Recommended certifications
CompTIA Security+CompTIA CySA+CompTIA PenTest+
Career progression

Cyber Fundamentals → Security+/CySA+ → Blue Team/Security Engineer.

What employers expect

That you understand core security principles and can apply them to real risks, controls and incidents.

Frequently asked questions

What is the difference between a vulnerability scan and a penetration test?

A scan automatically finds known weaknesses; a pen test is a manual, goal-driven simulated attack that exploits them.

What is CVSS?

The Common Vulnerability Scoring System — a 0–10 severity score used to help prioritise vulnerabilities.

Should you patch every vulnerability immediately?

No — prioritise by exploitability, exposure and business impact; not all vulnerabilities carry equal risk.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.