312-50V13 · Question #548
An IT company has just implemented new security controls to their network and system setup. As a Certified Ethical Hacker, your responsibility is to assess the possible vulnerabilities in the new…
The correct answer is A. Checking for hardware and software misconfigurations to identify any possible loopholes. Explanation Checking for hardware and software misconfigurations (Option A) is the best initial approach because even a fully patched and updated system can still be exploited if devices, applications, or network components are improperly configured - misconfigurations…
Question
Options
- AChecking for hardware and software misconfigurations to identify any possible loopholes
- BEvaluating the network for inherent technology weaknesses prone to specific types of attacks
- CInvestigating if any ex-employees still have access to the company's system and data
- DConducting social engineering tests to check if employees can be tricked into revealing sensitive
How the community answered
(36 responses)- A75% (27)
- B3% (1)
- C8% (3)
- D14% (5)
Explanation
Explanation
Checking for hardware and software misconfigurations (Option A) is the best initial approach because even a fully patched and updated system can still be exploited if devices, applications, or network components are improperly configured - misconfigurations represent one of the most common and easily overlooked vulnerability sources, regardless of patch status or training level. Option B (technology weaknesses) is less appropriate as the initial step because the scenario already confirms the system is patched, which largely mitigates known inherent technology vulnerabilities. Option C (ex-employee access) is a valid security concern but is a narrower, more specific check rather than a comprehensive initial vulnerability assessment strategy. Option D (social engineering) is also less suitable as the priority starting point because employees have already received recent cybersecurity awareness training, making this a lower-risk area compared to potential misconfigurations.
Memory Tip: Think of the acronym "PATCH + CONFIG = NOT ENOUGH" - just because a system is patched doesn't mean it's properly configured. Always check misconfigurations first when patches and training are already confirmed, as configuration errors are the gaps that remain.
Topics
Community Discussion
No community discussion yet for this question.