What you are evaluating
InsightVM remains the assessment engine inside the exposure SKU. Package entitlements, InsightVM migration, cloud-workload coverage, and retained evidence need to be confirmed per contract; the family name does not list those contents.
A useful evaluation context
A plausible evaluation context is an InsightVM estate testing whether Exposure Command inventory and enrichment actually change owner routing and retained evidence, not just the product label.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Surface Command inventory of assets as a distinct layer from vulnerability assessment.
- InsightVM retained as the scanner for vulnerability findings.
- Combination of vulnerability, cloud, and application findings with third-party enrichment inside Exposure Command.
Where it fits in the work
- Inventory owned assets with Surface Command sources, then run InsightVM assessment only where credentials, agents, or other entitled collectors are authorized.
- Compare Rapid7 findings with any third-party enrichment and keep exploitation and severity signals inspectable.
- Retain evidence through ticketing and re-assessment so a later reviewer can see what was found, owned, and verified closed.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In a lab subscription you own, place one host in Surface Command inventory and plant a missing patch that InsightVM can assess with lab credentials. Record a second lab host in an independent inventory you control, such as a lab configuration list or cloud export, but omit that host from scanner input.
Evidence to look for
The planted host is inventoried and assessed. The second host is visible as a coverage gap against that independent inventory, not as a previously unknown asset, and exportable evidence shows inventory, finding, owner, and verified close as separate records.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which exact packages are entitled, and what remains InsightVM-only after a move into Exposure Command?
- How is cloud-workload coverage demonstrated against the organization's actual accounts?
- What evidence is retained after a finding is closed, and can it be exported independently of the console?
Names you may encounter: InsightVM · Surface Command. Historical names do not establish current availability or feature equivalence.