Vulnerability and patch triage
Read vulnerability reports, decide what to patch first using severity, exploitation and exposure, and handle exceptions properly.
- Level
- Intermediate
- Length
- About 45 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Read a vulnerability finding: identifier, CVSS score and rating, affected asset and fix.
- Prioritise findings using known exploitation, exposure and asset importance as well as CVSS.
- Plan patch deployment in rings with a rollback option.
- Handle findings that can't be patched with documented compensating controls and an expiry date.
Course outline
- 1.Vulnerability and patch triageVideo · 5 min
- 2.Reading a vulnerability findingLesson · 8 min
- 3.Prioritising: exploitation, exposure and importanceLesson · 8 min
- 4.Patch rings, exceptions and verificationLesson · 8 min
- 5.Vulnerability and patch triage: knowledge checkKnowledge check · 17 questions
- 6.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- FIRST: Common Vulnerability Scoring System v3.1 Specification
- CISA: Known Exploited Vulnerabilities Catalog
- FIRST: Exploit Prediction Scoring System (EPSS)
- NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning
- Microsoft Learn: Microsoft Security Response Center: security update guide
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.