Vendor Security Response — Communication Vocabulary
Learn vocabulary for vendor responses to security researchers: acknowledgement, triage, and resolution language.
0 / 10 completed
1 / 10
What is the correct tone for the first response to a security researcher?
The first vendor response should: thank the researcher professionally, confirm receipt with a case/ticket number, and provide an expected triage timeline — building trust and encouraging continued responsible disclosure.
2 / 10
What does 'triage' mean in security response?
Triage is the process of evaluating a vulnerability report: verifying it reproduces, confirming its severity, identifying affected product versions, and determining the remediation priority.
3 / 10
What is a 'duplicate' in bug bounty vendor response?
A 'duplicate' means the vulnerability has already been reported (by this or another researcher) or is already known. The first reporter typically receives credit; subsequent reporters receive acknowledgement without a bounty.
4 / 10
What does 'out of scope' mean in vendor security response?
Out of scope means the reported issue falls outside the bug bounty programme's defined scope — e.g., DDoS attacks, social engineering, third-party services. Out-of-scope reports are acknowledged but not rewarded.
5 / 10
What is a 'patch verification' request from a security researcher?
Patch verification is when the researcher tests the vendor's fix to confirm it correctly addresses the reported vulnerability — an important step before joint disclosure, especially for complex vulnerabilities.
6 / 10
Sarah from the Incident Response team received this Slack message from a vendor: 'We've identified potential vulnerabilities in your API gateway. Please investigate immediately.' What is the most appropriate initial response to send back to Sarah?
The correct response requests specific information – a CVE ID or report link – which demonstrates proactive engagement and allows the Incident Response team to quickly assess the severity. Options A and C are dismissive or deflect responsibility; option D is overly dramatic without evidence of criticality. Asking for details immediately aligns with standard vendor security communication protocols.
7 / 10
David, a Senior Developer, is drafting the description for a Pull Request to update a library used in a high-traffic e-commerce application. The vendor has requested clarification on how they're tracking vulnerability remediation. Which of the following PR descriptions best communicates this information?
The best option provides a detailed explanation of the vendor's involvement and tracking mechanisms—specifically mentioning CVE IDs and timelines. Options A and B are too vague; simply stating 'fixed a bug' is insufficient. Option D is unprofessional and ignores the critical nature of the request.
8 / 10
Maria receives an API response from a security vendor detailing a potential SQL injection vulnerability in their application. The response includes a JSON payload like this: `{"status":"error", "code":403, "message":"Access denied - potential SQL injection attempt detected."}`. What does the 'code': 403 likely indicate?
A 403 status code (Forbidden) typically signifies that the server understands the request but refuses to authorize it. This strongly suggests that the vendor's system is actively blocking access related to the detected vulnerability – likely as a preventative measure before full remediation. Options A and C are incorrect; options B implies successful processing, which contradicts the message.
9 / 10
During a standup meeting, Ben (Security Engineer) says: 'The vendor reported a critical vulnerability and requested we immediately deploy an emergency patch. They've provided us with the updated code.' What is Ben most likely referring to when discussing 'deploying an emergency patch'?
When a vendor describes deploying an 'emergency patch,' they are referring to a rapid, often automated, release of updated code designed to address a critical security issue. This contrasts with a full audit (option A) or detailed assessment (option C), which would be slower processes. Option B is technically correct but less precise than the phrasing used.
10 / 10
Emily, a Security Analyst, is working with a vendor to investigate a potential data breach. The vendor requests confirmation that a specific set of logs (related to user authentication) have been retained for forensic analysis. What does 'patch verification' request from the vendor most likely entail?
'Patch verification' in this context refers to ensuring that you have adequately preserved and are providing access to the data required for investigation. This is crucial for determining the scope of the breach and identifying impacted systems. Options A and C represent broader security activities; option D is a reactive measure, not part of the initial verification process.
What will I learn from the "Vendor Security Response — Communication Vocabulary" exercise?
Learn vocabulary for vendor responses to security researchers: acknowledgement, triage, and resolution language.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall required.
How many questions are in this exercise?
This set contains 10 multiple-choice questions, each with a detailed explanation shown after you answer.
Do I need to create an account to track my progress?
No account is required. Your progress bar and score reset each time you reload the page, but you can retry the exercise as many times as you like.
Who is this Security Disclosure Language exercise for?
This exercise is built for IT professionals and non-native English speakers who need to read, write, and discuss security disclosure language topics confidently at work.
What happens if I answer a question incorrectly?
You will see the correct answer highlighted along with a detailed explanation of why it is correct -- so every wrong answer becomes a learning moment, not just a lost point.
Can I retry this exercise?
Yes -- click "Try again" on the results screen at any time to reset your score and go through all the questions again.
How long does this exercise take to complete?
Most learners finish all 10 questions in under 10 minutes, since each question is answered by clicking a single option.
Where can I find more Security Disclosure Language exercises?
See the full Security Disclosure Language exercises hub for more vocabulary drills on this topic.
Is this exercise mobile-friendly?
Yes -- the exercise works on any device with a modern browser, including phones and tablets, with no app download required.