Practice vocabulary for responsible disclosure: reporting vulnerabilities, following disclosure protocols, coordinating timelines, and public disclosure.
0 / 10 completed
1 / 10
When a security researcher contacts a vendor about a weakness they found, they would typically open with:
I've discovered a potential security vulnerability in your product — the word 'potential' is important; it's professional and non-accusatory.
2 / 10
When a researcher conducts their disclosure process according to established security community norms, they say they are:
Following responsible disclosure protocols signals professionalism — it means you notified the vendor privately before going public.
3 / 10
The standard window of time researchers give vendors to fix a vulnerability before publishing it publicly is called:
The 90-day disclosure timeline is the industry standard (established by Google Project Zero) — it balances vendor remediation time with public safety.
4 / 10
When a researcher asks the vendor to agree on when a fix will be released before publishing details, they say:
I'd like to coordinate on a remediation timeline — this collaborative phrasing keeps the relationship professional during the disclosure process.
5 / 10
When a vendor has not responded or fixed the issue and the researcher's deadline has passed, the researcher announces:
I'm disclosing publicly as the deadline has passed — this is the standard professional phrasing for publishing after the agreed deadline expires.
6 / 10
Liam, a security researcher, is contacting Acme Corp about a potential cross-site scripting (XSS) vulnerability in their JavaScript UI library. He wants to start the conversation professionally. Which of the following statements would be the most appropriate initial message?
Liam needs to establish trust and focus on the issue. Option 1 directly addresses the vulnerability and proposes a constructive conversation without alarmist language. Options 2 & 3 are too informal or vague, while option 4 is overly aggressive and could damage the relationship before any discussion begins. The goal here is clear communication of concern and intent.
7 / 10
Sarah, a senior developer, finds this comment in a code review:
'This function uses a deprecated method. Consider updating to the newer API.'
What is the best way for Sarah to respond to David, who wrote the code?
Sarah needs to acknowledge David's feedback and show a willingness to address the issue. Option 1 is passive and doesn't demonstrate action. Option 2 shows understanding and commitment to updating the code. Options 3 and 4 are dismissive or confused, failing to engage with the constructive feedback.
8 / 10
Ben, a developer, receives this message in a Slack channel related to a new API:
'Received a response from the API. Status code: 403. Error message: 'Forbidden'. Request URL: /users/profile'
What should Ben do next when investigating this issue?
A 403 status code indicates an authorization problem. Ben needs to investigate the root cause rather than simply repeating the request or dismissing the error. Checking authentication headers is a crucial first step in diagnosing API access issues. Options 3 and 4 are inappropriate responses that don't address the underlying technical problem.
9 / 10
Maria is writing a pull request description for a fix to a bug in a web application. She wants to clearly communicate her responsible disclosure process. Which sentence would be the MOST appropriate addition to the PR description?
'I've fixed a security vulnerability that could allow an attacker to inject malicious JavaScript code into our website.'
Maria needs to demonstrate transparency and adherence to responsible disclosure. This option explicitly states that she followed standard practices and shared details with the vendor (Acme Corp) for review – highlighting key elements of a good disclosure process. The other options omit critical information or provide an oversimplified explanation.
10 / 10
Tom is giving a brief update during the daily stand-up meeting. He says: 'I've found and reported a potential security issue to the development team.'
What should Tom do immediately after this statement?
During a stand-up, brevity is key. Tom's statement acknowledges the issue and commits to investigation without overwhelming the team with technical details at that moment. Option 2 demonstrates proactive communication and sets expectations for updates, while options 3 & 4 are too vague or alarmist.
What will I learn from the "Responsible Disclosure Communication" exercise?
Practice vocabulary for responsible disclosure: reporting vulnerabilities, following disclosure protocols, coordinating timelines, and public disclosure.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall required.
How many questions are in this exercise?
This set contains 10 multiple-choice questions, each with a detailed explanation shown after you answer.
Do I need to create an account to track my progress?
No account is required. Your progress bar and score reset each time you reload the page, but you can retry the exercise as many times as you like.
Who is this Security Disclosure Language exercise for?
This exercise is built for IT professionals and non-native English speakers who need to read, write, and discuss security disclosure language topics confidently at work.
What happens if I answer a question incorrectly?
You will see the correct answer highlighted along with a detailed explanation of why it is correct -- so every wrong answer becomes a learning moment, not just a lost point.
Can I retry this exercise?
Yes -- click "Try again" on the results screen at any time to reset your score and go through all the questions again.
How long does this exercise take to complete?
Most learners finish all 10 questions in under 10 minutes, since each question is answered by clicking a single option.
Where can I find more Security Disclosure Language exercises?
See the full Security Disclosure Language exercises hub for more vocabulary drills on this topic.
Is this exercise mobile-friendly?
Yes -- the exercise works on any device with a modern browser, including phones and tablets, with no app download required.