312-50V10 · Question #735
You have just been hired to perform a pen test on an organization that has been subjected to a large-scale attack. The CIO is concerned with mitigating threats and vulnerabilities to totally eliminate
The correct answer is C. Explain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to. A fundamental principle of risk management is that risk can be reduced or mitigated but never fully eliminated, so setting accurate expectations with the CIO is a critical first step.
Question
You have just been hired to perform a pen test on an organization that has been subjected to a large-scale attack. The CIO is concerned with mitigating threats and vulnerabilities to totally eliminate risk. What is one of the first things you should do when given the job?
Options
- AEstablish attribution to suspected attackers
- BInterview all employees in the company to rule out possible insider threats
- CExplain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to
- DStart the wireshark application to start sniffing network traffic.
How the community answered
(30 responses)- A7% (2)
- B7% (2)
- C70% (21)
- D17% (5)
Why each option
A fundamental principle of risk management is that risk can be reduced or mitigated but never fully eliminated, so setting accurate expectations with the CIO is a critical first step.
Attribution of attackers is a forensic or threat intelligence activity that typically occurs after an incident response, not as a first step in scoping a penetration test.
Interviewing all employees is a time-intensive insider threat investigation process that is outside the typical scope and first steps of a penetration test engagement.
No organization can achieve zero risk because new threats, unknown vulnerabilities, and human factors always introduce residual risk. Before beginning any engagement, a penetration tester must establish scope and expectations, which includes informing the CIO that the goal is to reduce risk to an acceptable level rather than eliminate it entirely. Failing to set this expectation leads to unrealistic success criteria and poor security decision-making.
Launching Wireshark to capture traffic is a technical reconnaissance activity that should only begin after the rules of engagement, scope, and legal authorization have been formally established.
Concept tested: Risk cannot be fully eliminated - residual risk concept
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.