nerdexam
CompTIA

CAS-003 · Question #256

A security firm is writing a response to an RFP from a customer that is building a new network based software product. The firm's expertise is in penetration testing corporate networks. The RFP…

The correct answer is A. Code review E. White box testing. A Code review refers to the examination of an application (the new network based software product in this case) that is designed to identify and assess threats to the organization. White box testing assumes that the penetration test team has full knowledge of the network and…

Enterprise Security Operations

Question

A security firm is writing a response to an RFP from a customer that is building a new network based software product. The firm's expertise is in penetration testing corporate networks. The RFP explicitly calls for all possible behaviors of the product to be tested, however, it does not specify any particular method to achieve this goal. Which of the following should be used to ensure the security and functionality of the product? (Select TWO).

Options

  • ACode review
  • BPenetration testing
  • CGrey box testing
  • DCode signing
  • EWhite box testing

How the community answered

(19 responses)
  • A
    84% (16)
  • C
    11% (2)
  • D
    5% (1)

Explanation

A Code review refers to the examination of an application (the new network based software product in this case) that is designed to identify and assess threats to the organization. White box testing assumes that the penetration test team has full knowledge of the network and the infrastructure per se thus rendering the testing to follow a more structured approach.

Topics

#white box testing#code review#software security testing#security assessment methodology

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice