nerdexam
EC-Council

312-50V9 · Question #360

If you are to determine the attack surface of an organization, which of the following is the BEST thing to do?

The correct answer is A. Running a network scan to detect network services in the corporate DMZ. Determining an organization's attack surface requires identifying all exposed and reachable services and entry points that an attacker could target. A network scan of the DMZ directly enumerates externally accessible services and open ports.

Introduction to Ethical Hacking

Question

If you are to determine the attack surface of an organization, which of the following is the BEST thing to do?

Options

  • ARunning a network scan to detect network services in the corporate DMZ
  • BReviewing the need for a security clearance for each employee
  • CUsing configuration management to determine when and where to apply security patches
  • DTraining employees on the security policy regarding social engineering

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    7% (2)
  • C
    18% (5)
  • D
    4% (1)

Why each option

Determining an organization's attack surface requires identifying all exposed and reachable services and entry points that an attacker could target. A network scan of the DMZ directly enumerates externally accessible services and open ports.

ARunning a network scan to detect network services in the corporate DMZCorrect

Running a network scan against the corporate DMZ identifies all live hosts, open ports, and running services that are exposed and reachable - these constitute the external attack surface. This is the most direct technical method for mapping what an attacker could target. Other options address security posture improvements but do not enumerate the actual attack surface.

BReviewing the need for a security clearance for each employee

Reviewing security clearance requirements is an access control and personnel security activity, not a method for identifying technical attack surfaces.

CUsing configuration management to determine when and where to apply security patches

Using configuration management to schedule patching addresses vulnerability remediation, not the identification or mapping of the attack surface itself.

DTraining employees on the security policy regarding social engineering

Training employees on social engineering policies is a people-focused defensive control and does not directly identify or enumerate technical attack vectors.

Concept tested: Attack surface analysis via network reconnaissance

Source: https://www.nist.gov/publications/attack-surface-definition-and-measurement

Topics

#attack surface#network scanning#DMZ#security assessment

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice