nerdexam
CompTIA

CAS-002 · Question #580

An organization must comply with a new regulation that requires the organization to determine if an external attacker is able to gain access to its systems from outside the network. Which of the…

The correct answer is C. Conduct a black box penetration test. A black box penetration test simulates a real external attacker with no prior knowledge of the internal environment, directly validating whether an outsider can breach organizational defenses. This is the only option that actively confirms exploitability from an external…

Research and Analysis

Question

An organization must comply with a new regulation that requires the organization to determine if an external attacker is able to gain access to its systems from outside the network. Which of the following should the company conduct to meet the regulation's criteria?

Options

  • AConduct a compliance review
  • BConduct a vulnerability assessment
  • CConduct a black box penetration test
  • DConduct a full system audit

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    6% (2)
  • C
    74% (26)
  • D
    14% (5)

Why each option

A black box penetration test simulates a real external attacker with no prior knowledge of the internal environment, directly validating whether an outsider can breach organizational defenses. This is the only option that actively confirms exploitability from an external perspective.

AConduct a compliance review

A compliance review evaluates whether existing controls align with policy or regulatory requirements on paper but does not actively test whether an attacker could actually breach the systems.

BConduct a vulnerability assessment

A vulnerability assessment identifies and catalogues weaknesses but stops short of active exploitation, so it cannot confirm whether an external attacker would successfully gain access through those weaknesses.

CConduct a black box penetration testCorrect

A black box penetration test replicates the exact scenario described by the regulation - an external attacker with no insider knowledge attempting to gain access - by actively exploiting vulnerabilities, which directly confirms or denies whether the organization's perimeter defenses can be breached from outside.

DConduct a full system audit

A full system audit examines system configurations and controls for accuracy and alignment with policy but does not simulate real-world external attack scenarios or validate exploitability.

Concept tested: Black box penetration testing for external threat validation

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#penetration testing#black box testing#compliance#external threats

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice