Responsible Disclosure — Vocabulary and Communication Language
Learn vocabulary for coordinated vulnerability disclosure: timelines, embargos, and vendor communication.
0 / 10 completed
1 / 10
What is 'coordinated vulnerability disclosure' (CVD)?
Coordinated Vulnerability Disclosure (CVD) is the process where a researcher notifies the vendor privately, a fix is developed, and details are published together — balancing security improvement with public transparency.
2 / 10
What does 'embargo period' mean in coordinated disclosure?
An embargo period is the agreed time during which vulnerability details are kept private — typically 90 days from disclosure to the vendor — giving time to develop and deploy a patch.
3 / 10
What is 'full disclosure' in vulnerability disclosure policy?
Full disclosure means publishing all technical details of a vulnerability publicly — typically invoked when a vendor fails to fix within the embargo period. It pressures vendors to patch while informing defenders.
4 / 10
What is a 'security.txt' file?
security.txt (RFC 9116) is a standardised file that tells security researchers where and how to report vulnerabilities — including contact email, PGP key, policy URL, and preferred languages.
5 / 10
What is 'vendor communication' best practice in responsible disclosure?
Best practice: use the official security contact (security@ or HackerOne/Bugcrowd programme), keep timestamped records of all communications, and get written agreement on the disclosure timeline.
6 / 10
Sarah, a security researcher at TechCorp, has discovered a cross-site scripting (XSS) vulnerability in the company's public-facing API. She needs to inform her team through Slack. Which of the following messages best demonstrates responsible disclosure?
The correct response demonstrates professionalism and prioritizes a controlled disclosure process. It avoids sensationalized language and immediately proposes a private discussion for coordinated action. Options A and D are overly aggressive or inappropriate. Option C is too casual; it doesn't explicitly state the need to coordinate.
7 / 10
David, a developer reviewing a pull request for a new e-commerce platform, notices a potential SQL injection vulnerability. The PR description includes the following line: 'This code sanitizes all user input to prevent malicious attacks.' What is the MOST appropriate comment David should leave on the PR?
David should probe for specifics regarding the security measures. Simply stating 'Great job!' offers no critical evaluation. Option A is complacent and doesn't encourage deeper investigation. Option C reflects a lack of focus, while option D avoids direct engagement with the security concern.
8 / 10
Maria is drafting a pull request to update a library used in a mobile app. As part of her responsible disclosure process, she includes a note in the PR description: 'I've identified a potential race condition. I will provide a detailed report and steps for remediation privately after confirming this with the vendor.' What does this statement primarily convey?
Maria's statement clearly outlines a controlled disclosure approach. It emphasizes the importance of validating the vulnerability with the vendor before public release and highlights her intention to work collaboratively. Options A and D are irresponsible; options B is incorrect – she isn't claiming ownership.
9 / 10
John, a security engineer, receives an API response from a third-party service indicating a critical vulnerability. The response includes the following JSON: `{"status": "critical", "vulnerability_id": "CVE-2023-XXXX", "description": "Unauthenticated access to sensitive data.", "remediation": "Implement authentication and authorization."}`. What is John's PRIMARY next step?
John's immediate priority is to formally report the vulnerability to the vendor. The API response provides key details for this purpose. Option A is wrong – public disclosure should be delayed until coordinated. Options C and D are not aligned with responsible disclosure best practices.
10 / 10
Emily is giving a standup update to her team about security work. She states, 'I've been investigating a potential denial-of-service (DoS) attack vector in our load balancer configuration.' What crucial element should she *immediately* add to her communication to ensure responsible disclosure?
Emily needs to signal her intention to engage with the relevant vendor. This demonstrates proactive collaboration and initiates a formal communication channel. Options A and B are overly alarming or provide no commitment to action; option D is important but not the *immediate* priority – contacting the vendor first is crucial.
What will I learn from the "Responsible Disclosure — Vocabulary and Communication Language" exercise?
Learn vocabulary for coordinated vulnerability disclosure: timelines, embargos, and vendor communication.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall required.
How many questions are in this exercise?
This set contains 10 multiple-choice questions, each with a detailed explanation shown after you answer.
Do I need to create an account to track my progress?
No account is required. Your progress bar and score reset each time you reload the page, but you can retry the exercise as many times as you like.
Who is this Security Disclosure Language exercise for?
This exercise is built for IT professionals and non-native English speakers who need to read, write, and discuss security disclosure language topics confidently at work.
What happens if I answer a question incorrectly?
You will see the correct answer highlighted along with a detailed explanation of why it is correct -- so every wrong answer becomes a learning moment, not just a lost point.
Can I retry this exercise?
Yes -- click "Try again" on the results screen at any time to reset your score and go through all the questions again.
How long does this exercise take to complete?
Most learners finish all 10 questions in under 10 minutes, since each question is answered by clicking a single option.
Where can I find more Security Disclosure Language exercises?
See the full Security Disclosure Language exercises hub for more vocabulary drills on this topic.
Is this exercise mobile-friendly?
Yes -- the exercise works on any device with a modern browser, including phones and tablets, with no app download required.