nerdexam
CompTIA

CAS-002 · Question #154

A security consultant is hired by a company to determine if an internally developed web application is vulnerable to attacks. The consultant spent two weeks testing the application, and determines…

The correct answer is D. There are no known vulnerabilities at this time. Security testing can only identify vulnerabilities that are detectable with the tools and techniques used at the time of testing. It cannot prove the complete absence of vulnerabilities - new vulnerabilities are discovered continuously, and some may not yet be known or have…

Research and Analysis

Question

A security consultant is hired by a company to determine if an internally developed web application is vulnerable to attacks. The consultant spent two weeks testing the application, and determines that no vulnerabilities are present. Based on the results of the tools and tests available, which of the following statements BEST reflects the security status of the application?

Options

  • AThe company's software lifecycle management improved the security of the application.
  • BThere are no vulnerabilities in the application.
  • CThe company should deploy a web application firewall to ensure extra security.
  • DThere are no known vulnerabilities at this time.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    4% (1)
  • D
    84% (21)

Explanation

Security testing can only identify vulnerabilities that are detectable with the tools and techniques used at the time of testing. It cannot prove the complete absence of vulnerabilities - new vulnerabilities are discovered continuously, and some may not yet be known or have published detection methods. The correct and appropriately qualified statement is that 'there are no known vulnerabilities at this time.' Option B ('no vulnerabilities exist') is an absolute claim that cannot be supported by any finite test. Option A attributes the result to SDLC improvements without evidence. Option C (deploy a WAF) is a separate recommendation not supported by the testing outcome alone.

Topics

#penetration testing#vulnerability assessment#testing limitations#web application security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice