Security Remediation — Vocabulary and Communication
Learn vocabulary for tracking and communicating security vulnerability remediation: retest, risk acceptance, and remediation status.
0 / 10 completed
1 / 10
What is a 'retest' in penetration testing vocabulary?
A retest is a targeted follow-up assessment — not a full pentest — focused specifically on verifying that previously identified vulnerabilities have been fixed. The tester re-runs the same exploitation steps and confirms either 'Remediated' or 'Still Vulnerable.'
2 / 10
What is 'risk acceptance' in security remediation vocabulary?
Risk acceptance is a formal, documented decision: 'We know about this vulnerability, we choose not to fix it because [cost/complexity/low impact], and [Name/Role] accepts ownership of this risk.' Risk acceptance should be time-limited and periodically reviewed.
3 / 10
What is 'compensating control' in security remediation vocabulary?
A compensating control mitigates risk when direct remediation is impossible or too costly. Example: if a vulnerable legacy system cannot be patched, compensating controls might include network isolation, enhanced monitoring, and WAF rules that block known exploit patterns.
4 / 10
What does 'remediation status' mean in a security tracking context?
Remediation status tracks each finding through its lifecycle: Open (unaddressed), In Progress (fix being developed), Remediated (fix deployed, pending verification), Verified Remediated (confirmed by retest), or Risk Accepted/Mitigated. This tracking is often maintained in a remediation tracker shared between tester and client.
5 / 10
What is a 'remediation SLA' in security context?
A remediation SLA sets expected timelines for fixing vulnerabilities by severity. Common SLAs: Critical (24–72 hours), High (7–14 days), Medium (30 days), Low (90 days). Organizations use these to prioritize security work and measure remediation performance.
6 / 10
Liam (Senior Security Engineer) posted this to Slack: 'Just ran a quick scan on the new API endpoint. Found some potential vulnerabilities – let's discuss mitigation strategies ASAP.' What does Liam *most likely* mean when he uses the term 'mitigation strategies' in this context?
Liam is referring to actions taken to reduce the *impact* of the vulnerabilities he found. 'Mitigation strategies' involves steps like fixing code or configuring defenses—not simply blocking traffic (option A) or relying on an external audit (option C). Option D is completely inappropriate for a security engineer.
7 / 10
During a code review of a new authentication service, Sarah (Junior Developer) receives this comment from David (Senior Architect): 'This implementation lacks proper input validation. We need to explicitly check for potentially malicious characters and prevent SQL injection.' What is David primarily advocating for regarding security remediation?
David is requesting a specific technical fix – input validation – to address a concrete security risk (SQL injection). Options A, B and D are all valid security practices but aren't directly what David is addressing in this code review comment. Input validation is the most immediate response to the identified vulnerability.
8 / 10
You are documenting a security remediation task for a critical vulnerability discovered in a web application. The task description states: 'The fix is deployed and verified. We have implemented compensating controls to reduce the risk while awaiting full resolution.' What does 'compensating controls' refer to?
'Compensating controls' are temporary safeguards implemented when a full remediation isn't immediately possible. This acknowledges that while the primary fix is in progress, other measures must be taken to limit potential harm—unlike permanent architectural changes (option A) or simply documenting the root cause (option D).
9 / 10
Mark (Security Operations Analyst) is updating a ticket regarding a recently remediated vulnerability. The ticket status reads: 'Remediation Complete – Waiting for Verification.' What does the 'Remediation Status' field primarily indicate?
'Remediation Status' is a key indicator of progress – specifically, that the *action* to fix the vulnerability has been taken. It doesn't detail the technical specifics (option A) or define a deadline (option B), but reflects the current state of completion. Severity level would be found elsewhere.
10 / 10
During a project retrospective, Anna (Project Manager) discusses the security remediation process for a recent incident. She mentions: 'We agreed to a remediation SLA of 72 hours for all high-severity vulnerabilities.' What does this 'SLA' represent in the context of security remediation?
'SLA' stands for Service Level Agreement – in this case, a commitment about response time. It's not a legal agreement (option A) or a technical specification (option C), but rather a contractual guarantee regarding how quickly a security issue needs to be addressed. Option D is an audit process.
What will I practise in "Security Remediation — Vocabulary and Communication"?
This module focuses on Pentest Communication — real workplace phrasing you'll use on the job. It contains 10 scenario-based multiple-choice questions with instant feedback.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account or sign-up required.
How many questions does this exercise have?
This module includes 10 questions. Each one gives an immediate right/wrong result plus a full explanation of the correct phrasing.
What happens if I answer a question incorrectly?
You'll see the correct answer highlighted straight away, along with a plain-English explanation of why it's right and why the other options don't fit — mistakes are part of the learning here.
Can I retry the exercise if I want a better score?
Yes — use the 'Try again' button on the results screen to reset your score and go through the questions again. There's no limit on attempts.
Who is this Pentest Communication exercise for?
It's aimed at IT professionals with working English who want to sound more natural and precise around pentest communication — useful whether you're preparing for real conversations at work or just building confidence with the vocabulary.
Do I need an account to track my progress?
No account is needed. Your progress through the exercise is tracked locally in your browser for the current session, and you can replay the module at any time.
How is this different from reading a blog article?
This exercise is an interactive drill that tests and reinforces specific phrasing through multiple-choice questions with instant feedback, while blog articles explain concepts and vocabulary in prose. The two work well together.
Where can I find more Pentest Communication exercises?
See the Pentest Communication hub for more modules like this one, or browse the full Exercises page for other IT-English topics.
Can I complete this exercise on my phone?
Yes — every exercise on CoderSlingo is fully responsive and works on phones and tablets, so you can practise anywhere.