312-50V12 · Question #190
An IT company has just implemented new security controls to their network and system setup. As a Certified Ethical Hacker, your responsibility is to assess the possible vulnerabilities in the new…
The correct answer is B. Checking for hardware and software misconfigurations to identify any possible loopholes. For a newly implemented and patched IT setup with trained employees, the best initial vulnerability assessment approach is to identify hardware and software misconfigurations.
Question
Options
- AConducting social engineering tests to check if employees can be tricked into revealing sensitive
- BChecking for hardware and software misconfigurations to identify any possible loopholes
- CEvaluating the network for inherent technology weaknesses prone to specific types of attacks
- DInvestigating if any ex-employees still have access to the company's system and data
How the community answered
(26 responses)- A8% (2)
- B73% (19)
- C15% (4)
- D4% (1)
Why each option
For a newly implemented and patched IT setup with trained employees, the best initial vulnerability assessment approach is to identify hardware and software misconfigurations.
While social engineering is a valid vulnerability, the question states employees received training, and checking for fundamental system misconfigurations is a more foundational initial assessment step for a new setup than immediately testing human susceptibility.
Misconfigurations are a common and critical source of vulnerabilities in new IT deployments, encompassing issues like default credentials, unneeded open ports, insecure protocols, and incorrect access controls. Addressing these technical settings first provides a broad security improvement before focusing on less immediate or more specific threat vectors in a new setup.
Evaluating 'inherent technology weaknesses' refers to fundamental design flaws, which are less likely to be the initial focus for a patched system assessment compared to common implementation errors like misconfigurations.
Investigating ex-employee access is a specific access control check, which is important but often falls under the broader category of misconfigurations or access management flaws, making a comprehensive configuration review a more encompassing initial approach.
Concept tested: Initial vulnerability assessment strategies; misconfiguration vulnerability
Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/vulnerability-assessment-overview
Topics
Community Discussion
No community discussion yet for this question.