nerdexam
EC-Council

312-50V12 · Question #25

Jude, a pen tester, examined a network from a hacker's perspective to identify exploits and vulnerabilities accessible to the outside world by using devices such as firewalls, routers, and servers…

The correct answer is B. External assessment. Jude performed an external vulnerability assessment by evaluating the network from an outside attacker's perspective, targeting perimeter devices like firewalls, routers, and servers exposed to the internet.

Submitted by zhang_li· Mar 4, 2026Network and Perimeter Hacking

Question

Jude, a pen tester, examined a network from a hacker's perspective to identify exploits and vulnerabilities accessible to the outside world by using devices such as firewalls, routers, and servers. In this process, he also estimated the threat of network security attacks and determined the level of security of the corporate network. What is the type of vulnerability assessment that Jude performed on the organization?

Options

  • AApplication assessment
  • BExternal assessment
  • CPassive assessment
  • DHost-based assessment

How the community answered

(27 responses)
  • B
    93% (25)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Jude performed an external vulnerability assessment by evaluating the network from an outside attacker's perspective, targeting perimeter devices like firewalls, routers, and servers exposed to the internet.

AApplication assessment

An application assessment focuses specifically on vulnerabilities within software applications, such as web apps or databases, rather than evaluating the overall network perimeter and infrastructure devices.

BExternal assessmentCorrect

An external assessment is specifically conducted from the perspective of an outside attacker, focusing on vulnerabilities accessible from outside the network perimeter through internet-facing devices such as firewalls, routers, and servers. This type of assessment estimates the threat posed by external network security attacks and measures the overall security posture of the corporate network boundary. It mirrors what a real-world hacker would see and attempt to exploit from outside the organization.

CPassive assessment

A passive assessment involves monitoring and analyzing network traffic without actively probing systems, whereas Jude actively examined exploits and vulnerabilities from an attacker's perspective.

DHost-based assessment

A host-based assessment focuses on vulnerabilities on individual hosts or endpoints (such as OS configurations, patches, and local services) rather than evaluating the external network perimeter and its devices.

Concept tested: Types of vulnerability assessments in penetration testing

Source: https://www.eccouncil.org/cybersecurity-exchange/penetration-testing/types-of-vulnerability-assessment/

Topics

#vulnerability assessment#external assessment#network security

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice