nerdexam
EC-Council

312-50V11 · Question #395

Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design, and implementation?

The correct answer is A. Penetration testing. Penetration testing provides the most comprehensive security assessment by actively testing policy, procedure design, and implementation in a manner that simulates real-world attacks.

Information Security and Ethical Hacking Fundamentals

Question

Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design, and implementation?

Options

  • APenetration testing
  • BSocial engineering
  • CVulnerability scanning
  • DAccess control list reviews

How the community answered

(45 responses)
  • A
    93% (42)
  • C
    2% (1)
  • D
    4% (2)

Why each option

Penetration testing provides the most comprehensive security assessment by actively testing policy, procedure design, and implementation in a manner that simulates real-world attacks.

APenetration testingCorrect

Penetration testing goes beyond identifying vulnerabilities by actively attempting to exploit them, which validates whether security controls work as designed across policy, architecture, and operational layers. This end-to-end validation demonstrates real risk exposure, making it easier to justify security investments with concrete evidence of what an attacker could achieve. The comprehensive scope covering people, processes, and technology yields the strongest return on security investment.

BSocial engineering

Social engineering is a technique used within a penetration test, not a standalone assessment methodology that covers policy and procedure design comprehensively.

CVulnerability scanning

Vulnerability scanning identifies known weaknesses automatically but does not verify exploitability, assess policy effectiveness, or evaluate procedural controls.

DAccess control list reviews

Access control list reviews examine only permission configurations and do not assess broader security posture, implementation effectiveness, or return on investment.

Concept tested: Penetration testing scope and security investment return

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#penetration testing#security assessment#ROI#comprehensive testing

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice