nerdexam
EC-Council

112-52 · Question #139

What is a key benefit of conducting penetration testing?

The correct answer is A. Validating compliance with security policies. Penetration testing simulates real-world attacks to uncover vulnerabilities before malicious actors do, and its primary value lies in validating that security policies and controls actually work as intended - not just that they exist on paper. Option A is correct because pen…

Ethical Hacking Fundamentals

Question

What is a key benefit of conducting penetration testing?

Options

  • AValidating compliance with security policies
  • BIncreasing the efficiency of IT operations
  • CEnhancing the physical security of data centers
  • DReducing the need for IT training

How the community answered

(31 responses)
  • A
    90% (28)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Penetration testing simulates real-world attacks to uncover vulnerabilities before malicious actors do, and its primary value lies in validating that security policies and controls actually work as intended - not just that they exist on paper. Option A is correct because pen tests produce evidence-based findings that confirm (or refute) compliance with security standards like PCI-DSS, ISO 27001, or internal policies.

Why the distractors are wrong:

  • B is wrong because pen testing is a security assurance activity, not an IT efficiency tool - it can even temporarily disrupt operations.
  • C is wrong because pen testing is focused on logical/digital attack surfaces (networks, applications, credentials), not physical infrastructure like server rooms.
  • D is wrong because pen testing findings often increase the need for security training by exposing skill and awareness gaps.

Memory tip: Think of pen testing as a "proof of protection" exercise - you're testing whether your security policies hold up under attack, which maps directly to validation of compliance. The word "penetrate" implies probing defenses, and defenses are defined by policies.

Topics

#Penetration Testing#Compliance Validation#Security Assessment#Risk Identification

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice