nerdexam
EC-Council

312-50V12 · Question #190

An IT company has just implemented new security controls to their network and system setup. As a Certified Ethical Hacker, your responsibility is to assess the possible vulnerabilities in the new…

The correct answer is B. Checking for hardware and software misconfigurations to identify any possible loopholes. For a newly implemented and patched IT setup with trained employees, the best initial vulnerability assessment approach is to identify hardware and software misconfigurations.

Submitted by kevin_r· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

An IT company has just implemented new security controls to their network and system setup. As a Certified Ethical Hacker, your responsibility is to assess the possible vulnerabilities in the new setup. You are given the information that the network and system are adequately patched with the latest updates, and all employees have gone through recent cybersecurity awareness training. Considering the potential vulnerability sources, what is the best initial approach to vulnerability assessment?

Options

  • AConducting social engineering tests to check if employees can be tricked into revealing sensitive
  • BChecking for hardware and software misconfigurations to identify any possible loopholes
  • CEvaluating the network for inherent technology weaknesses prone to specific types of attacks
  • DInvestigating if any ex-employees still have access to the company's system and data

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    73% (19)
  • C
    15% (4)
  • D
    4% (1)

Why each option

For a newly implemented and patched IT setup with trained employees, the best initial vulnerability assessment approach is to identify hardware and software misconfigurations.

AConducting social engineering tests to check if employees can be tricked into revealing sensitive

While social engineering is a valid vulnerability, the question states employees received training, and checking for fundamental system misconfigurations is a more foundational initial assessment step for a new setup than immediately testing human susceptibility.

BChecking for hardware and software misconfigurations to identify any possible loopholesCorrect

Misconfigurations are a common and critical source of vulnerabilities in new IT deployments, encompassing issues like default credentials, unneeded open ports, insecure protocols, and incorrect access controls. Addressing these technical settings first provides a broad security improvement before focusing on less immediate or more specific threat vectors in a new setup.

CEvaluating the network for inherent technology weaknesses prone to specific types of attacks

Evaluating 'inherent technology weaknesses' refers to fundamental design flaws, which are less likely to be the initial focus for a patched system assessment compared to common implementation errors like misconfigurations.

DInvestigating if any ex-employees still have access to the company's system and data

Investigating ex-employee access is a specific access control check, which is important but often falls under the broader category of misconfigurations or access management flaws, making a comprehensive configuration review a more encompassing initial approach.

Concept tested: Initial vulnerability assessment strategies; misconfiguration vulnerability

Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/vulnerability-assessment-overview

Topics

#vulnerability assessment#misconfiguration#security audit#initial assessment

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice