312-50V11 · Question #42
Which of the following provides a security professional with most information about the system's security posture?
The correct answer is D. Port scanning, banner grabbing, service identification. Port scanning, banner grabbing, and service identification provide direct technical evidence of open ports, running software, and version details - giving the most comprehensive and actionable view of a system's security posture.
Question
Which of the following provides a security professional with most information about the system's security posture?
Options
- AWardriving, warchalking, social engineering
- BSocial engineering, company site browsing, tailgating
- CPhishing, spamming, sending trojans
- DPort scanning, banner grabbing, service identification
How the community answered
(15 responses)- B7% (1)
- D93% (14)
Why each option
Port scanning, banner grabbing, and service identification provide direct technical evidence of open ports, running software, and version details - giving the most comprehensive and actionable view of a system's security posture.
Wardriving, warchalking, and social engineering focus on wireless network discovery and human manipulation, providing limited insight into the specific technical security state of a target system.
Social engineering, company site browsing, and tailgating are passive or physical reconnaissance methods that reveal organizational information but do not assess the technical configuration or vulnerability exposure of systems.
Phishing, spamming, and deploying trojans are active offensive attack techniques aimed at compromising systems, not assessment methods used to evaluate an existing security posture.
Port scanning maps which ports are open and exposed, banner grabbing retrieves service banners that reveal specific software versions potentially affected by known CVEs, and service identification confirms exactly what is running and how it is configured. Together these three techniques produce concrete, technical data about the system's attack surface that can be directly matched against vulnerability databases. This combination is the foundation of any structured vulnerability assessment or penetration test.
Concept tested: Active technical reconnaissance for security posture assessment
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.