nerdexam
(ISC)2

CAP · Question #198

Which of the following NIST documents includes components for penetration testing?

The correct answer is D. NIST SP 800-30. NIST SP 800-30 (Guide for Conducting Risk Assessments) describes technical and procedural methods for assessing risk, including techniques such as penetration testing as part of the vulnerability and threat evaluation process. Among the options: SP 800-53 catalogs security and…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following NIST documents includes components for penetration testing?

Options

  • ANIST SP 800-53
  • BNIST SP 800-26
  • CNIST SP 800-37
  • DNIST SP 800-30

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    4% (2)
  • D
    91% (42)

Explanation

NIST SP 800-30 (Guide for Conducting Risk Assessments) describes technical and procedural methods for assessing risk, including techniques such as penetration testing as part of the vulnerability and threat evaluation process. Among the options: SP 800-53 catalogs security and privacy controls; SP 800-26 was a self-assessment guide for IT systems (now superseded); SP 800-37 defines the Risk Management Framework process. SP 800-30's risk assessment methodology encompasses active testing techniques like penetration testing to determine the exploitability of vulnerabilities.

Topics

#NIST Special Publications#Penetration Testing#Risk Assessment#Vulnerability Identification

Community Discussion

No community discussion yet for this question.

Full CAP Practice