312-50V12 · Question #25
Jude, a pen tester, examined a network from a hacker's perspective to identify exploits and vulnerabilities accessible to the outside world by using devices such as firewalls, routers, and servers…
The correct answer is B. External assessment. Jude performed an external vulnerability assessment by evaluating the network from an outside attacker's perspective, targeting perimeter devices like firewalls, routers, and servers exposed to the internet.
Question
Options
- AApplication assessment
- BExternal assessment
- CPassive assessment
- DHost-based assessment
How the community answered
(27 responses)- B93% (25)
- C4% (1)
- D4% (1)
Why each option
Jude performed an external vulnerability assessment by evaluating the network from an outside attacker's perspective, targeting perimeter devices like firewalls, routers, and servers exposed to the internet.
An application assessment focuses specifically on vulnerabilities within software applications, such as web apps or databases, rather than evaluating the overall network perimeter and infrastructure devices.
An external assessment is specifically conducted from the perspective of an outside attacker, focusing on vulnerabilities accessible from outside the network perimeter through internet-facing devices such as firewalls, routers, and servers. This type of assessment estimates the threat posed by external network security attacks and measures the overall security posture of the corporate network boundary. It mirrors what a real-world hacker would see and attempt to exploit from outside the organization.
A passive assessment involves monitoring and analyzing network traffic without actively probing systems, whereas Jude actively examined exploits and vulnerabilities from an attacker's perspective.
A host-based assessment focuses on vulnerabilities on individual hosts or endpoints (such as OS configurations, patches, and local services) rather than evaluating the external network perimeter and its devices.
Concept tested: Types of vulnerability assessments in penetration testing
Source: https://www.eccouncil.org/cybersecurity-exchange/penetration-testing/types-of-vulnerability-assessment/
Topics
Community Discussion
No community discussion yet for this question.