nerdexam
EC-Council

312-50V11 · Question #959

Jude, a pen tester, examined a network from a hacker's perspective to identify exploits and vulnerabilities accessible to the outside world by using devices such as firewalls, routers, and servers…

The correct answer is A. External assessment. Jude performed an external vulnerability assessment, which evaluates security threats and weaknesses accessible from outside an organization's network perimeter.

Vulnerability Analysis

Question

Jude, a pen tester, examined a network from a hacker's perspective to identify exploits and vulnerabilities accessible to the outside world by using devices such as firewalls, routers, and servers. In this process, he also estimated the threat of network security attacks and determined the level of security of the corporate network. What is the type of vulnerability assessment that Jude performed on the organization?

Options

  • AExternal assessment
  • BPassive assessment
  • CA Host-based assessment
  • DApplication assessment

How the community answered

(37 responses)
  • A
    89% (33)
  • B
    5% (2)
  • C
    3% (1)
  • D
    3% (1)

Why each option

Jude performed an external vulnerability assessment, which evaluates security threats and weaknesses accessible from outside an organization's network perimeter.

AExternal assessmentCorrect

An external vulnerability assessment examines the network strictly from an outside attacker's perspective, focusing on externally facing assets such as firewalls, routers, and servers. It identifies exploitable vulnerabilities accessible to the outside world and estimates the threat posed by external network attacks. This matches Jude's activity of analyzing perimeter defenses to determine the corporate network's overall security posture.

BPassive assessment

A passive assessment involves only monitoring and analyzing existing network traffic without actively probing or sending crafted packets to target systems.

CA Host-based assessment

A host-based assessment focuses on the security configuration and vulnerabilities of individual host systems rather than the organization's network perimeter.

DApplication assessment

An application assessment focuses specifically on identifying vulnerabilities within software applications rather than evaluating the broader network infrastructure and perimeter devices.

Concept tested: External vulnerability assessment of network perimeter

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#external assessment#vulnerability assessment types#penetration testing#network perimeter

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice