nerdexam
CompTIA

CAS-001 · Question #135

A security consultant is hired by a company to determine if an internally developed web application is vulnerable to attacks. The consultant spent two weeks testing the application, and determines…

The correct answer is D. There are no known vulnerabilities at this time. The most accurate and professionally defensible statement is 'There are no known vulnerabilities at this time.' Security testing can only identify vulnerabilities that are detectable by current tools and techniques within the scope and time of the engagement. It cannot prove…

Research and Analysis

Question

A security consultant is hired by a company to determine if an internally developed web application is vulnerable to attacks. The consultant spent two weeks testing the application, and determines that no vulnerabilities are present. Based on the results of the tools and tests available, which of the following statements BEST reflects the security status of the application?

Options

  • AThe company's software lifecycle management improved the security of the application.
  • BThere are no vulnerabilities in the application.
  • CThe company should deploy a web application firewall to ensure extra security.
  • DThere are no known vulnerabilities at this time.

How the community answered

(54 responses)
  • A
    11% (6)
  • B
    2% (1)
  • C
    6% (3)
  • D
    81% (44)

Explanation

The most accurate and professionally defensible statement is 'There are no known vulnerabilities at this time.' Security testing can only identify vulnerabilities that are detectable by current tools and techniques within the scope and time of the engagement. It cannot prove the complete absence of vulnerabilities - only that none were found. Option B ('There are no vulnerabilities') is an absolute claim that no testing methodology can support and would be misleading. Option A is an assumption about the SDLC not supported by the test results. Option C (deploying a WAF) is a recommendation that doesn't follow from the assessment results. This question reinforces a core security principle: absence of evidence is not evidence of absence.

Topics

#penetration testing#vulnerability assessment#testing limitations#application security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice