nerdexam
EC-Council

312-50V9 · Question #172

Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design, and implementation?

The correct answer is A. Penetration testing. Penetration testing delivers the best return on security investment by simulating real attacks and evaluating the full security posture including policies, procedures, and technical controls.

Introduction to Ethical Hacking

Question

Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design, and implementation?

Options

  • APenetration testing
  • BSocial engineering
  • CVulnerability scanning
  • DAccess control list reviews

How the community answered

(47 responses)
  • A
    89% (42)
  • B
    4% (2)
  • C
    2% (1)
  • D
    4% (2)

Why each option

Penetration testing delivers the best return on security investment by simulating real attacks and evaluating the full security posture including policies, procedures, and technical controls.

APenetration testingCorrect

Penetration testing goes beyond identifying vulnerabilities by actively attempting to exploit them, demonstrating actual business risk and validating whether security controls work as intended. It assesses the entire security program - policies, procedures, and technical implementation - providing a holistic view that justifies security spending. This comprehensive scope makes it the most effective method for demonstrating ROI on security investments.

BSocial engineering

Social engineering is a specific attack technique that may be used as part of a penetration test, not a standalone comprehensive assessment methodology.

CVulnerability scanning

Vulnerability scanning only identifies known technical weaknesses in systems and does not evaluate policies, procedures, or whether vulnerabilities are actually exploitable.

DAccess control list reviews

Access control list reviews examine only permission configurations on systems and cannot assess the broader organizational security posture including policy and procedure design.

Concept tested: Penetration testing scope and return on investment

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf

Topics

#penetration testing#security ROI#comprehensive assessment#security posture

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice