nerdexam
EC-Council

312-50V13 · Question #548

An IT company has just implemented new security controls to their network and system setup. As a Certified Ethical Hacker, your responsibility is to assess the possible vulnerabilities in the new…

The correct answer is A. Checking for hardware and software misconfigurations to identify any possible loopholes. Explanation Checking for hardware and software misconfigurations (Option A) is the best initial approach because even a fully patched and updated system can still be exploited if devices, applications, or network components are improperly configured - misconfigurations…

Submitted by ahmad_uae· Mar 6, 2026Vulnerability Analysis

Question

An IT company has just implemented new security controls to their network and system setup. As a Certified Ethical Hacker, your responsibility is to assess the possible vulnerabilities in the new setup. You are given the information that the network and system are adequately patched with the latest updates, and all employees have gone through recent cybersecurity awareness training. Considering the potential vulnerability sources, what is the best initial approach to vulnerability assessment?

Options

  • AChecking for hardware and software misconfigurations to identify any possible loopholes
  • BEvaluating the network for inherent technology weaknesses prone to specific types of attacks
  • CInvestigating if any ex-employees still have access to the company's system and data
  • DConducting social engineering tests to check if employees can be tricked into revealing sensitive

How the community answered

(36 responses)
  • A
    75% (27)
  • B
    3% (1)
  • C
    8% (3)
  • D
    14% (5)

Explanation

Explanation

Checking for hardware and software misconfigurations (Option A) is the best initial approach because even a fully patched and updated system can still be exploited if devices, applications, or network components are improperly configured - misconfigurations represent one of the most common and easily overlooked vulnerability sources, regardless of patch status or training level. Option B (technology weaknesses) is less appropriate as the initial step because the scenario already confirms the system is patched, which largely mitigates known inherent technology vulnerabilities. Option C (ex-employee access) is a valid security concern but is a narrower, more specific check rather than a comprehensive initial vulnerability assessment strategy. Option D (social engineering) is also less suitable as the priority starting point because employees have already received recent cybersecurity awareness training, making this a lower-risk area compared to potential misconfigurations.

Memory Tip: Think of the acronym "PATCH + CONFIG = NOT ENOUGH" - just because a system is patched doesn't mean it's properly configured. Always check misconfigurations first when patches and training are already confirmed, as configuration errors are the gaps that remain.

Topics

#Vulnerability Assessment#Security Misconfigurations#Initial Assessment Strategy#System Hardening

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice