nerdexam
CompTIA

CAS-003 · Question #126

Due to compliance regulations, a company requires a yearly penetration test. The Chief Information Security Officer (CISO) has asked that it be done under a black box methodology. Which of the…

The correct answer is D. The results should reflect what attackers may be able to learn about the company. A black box penetration test is usually done when you do not have access to the code, much the same like an outsider/attacker. This is then the best way to run a penetration test that will also reflect what an attacker/outsider can learn about the company. A black box test…

Enterprise Security Operations

Question

Due to compliance regulations, a company requires a yearly penetration test. The Chief Information Security Officer (CISO) has asked that it be done under a black box methodology. Which of the following would be the advantage of conducting this kind of penetration test?

Options

  • AThe risk of unplanned server outages is reduced.
  • BUsing documentation provided to them, the pen-test organization can quickly determine areas to
  • CThe results will show an in-depth view of the network and should help pin-point areas of internal
  • DThe results should reflect what attackers may be able to learn about the company.

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    4% (1)
  • D
    89% (24)

Explanation

A black box penetration test is usually done when you do not have access to the code, much the same like an outsider/attacker. This is then the best way to run a penetration test that will also reflect what an attacker/outsider can learn about the company. A black box test simulates an outsiders attack.

Topics

#black box testing#penetration testing#attacker simulation#compliance

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice