CAS-002 · Question #580
An organization must comply with a new regulation that requires the organization to determine if an external attacker is able to gain access to its systems from outside the network. Which of the…
The correct answer is C. Conduct a black box penetration test. A black box penetration test simulates a real external attacker with no prior knowledge of the internal environment, directly validating whether an outsider can breach organizational defenses. This is the only option that actively confirms exploitability from an external…
Question
An organization must comply with a new regulation that requires the organization to determine if an external attacker is able to gain access to its systems from outside the network. Which of the following should the company conduct to meet the regulation's criteria?
Options
- AConduct a compliance review
- BConduct a vulnerability assessment
- CConduct a black box penetration test
- DConduct a full system audit
How the community answered
(35 responses)- A6% (2)
- B6% (2)
- C74% (26)
- D14% (5)
Why each option
A black box penetration test simulates a real external attacker with no prior knowledge of the internal environment, directly validating whether an outsider can breach organizational defenses. This is the only option that actively confirms exploitability from an external perspective.
A compliance review evaluates whether existing controls align with policy or regulatory requirements on paper but does not actively test whether an attacker could actually breach the systems.
A vulnerability assessment identifies and catalogues weaknesses but stops short of active exploitation, so it cannot confirm whether an external attacker would successfully gain access through those weaknesses.
A black box penetration test replicates the exact scenario described by the regulation - an external attacker with no insider knowledge attempting to gain access - by actively exploiting vulnerabilities, which directly confirms or denies whether the organization's perimeter defenses can be breached from outside.
A full system audit examines system configurations and controls for accuracy and alignment with policy but does not simulate real-world external attack scenarios or validate exploitability.
Concept tested: Black box penetration testing for external threat validation
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.