nerdexam
CompTIA

CAS-003 · Question #368

A company has decided to lower costs by conducting an internal assessment on specific devices and various internal and external subnets. The assessment will be done during regular office hours, but…

The correct answer is C. Configuration review F. Tabletop exercise. An internal assessment that must avoid impacting production systems and reduce costs points to passive, non-intrusive methods - configuration review and tabletop exercises fit both constraints.

Enterprise Security Operations

Question

A company has decided to lower costs by conducting an internal assessment on specific devices and various internal and external subnets. The assessment will be done during regular office hours, but it must not affect any production servers. Which of the following would MOST likely be used to complete the assessment? (Select two.)

Options

  • AAgent-based vulnerability scan
  • BBlack-box penetration testing
  • CConfiguration review
  • DSocial engineering
  • EMalware sandboxing
  • FTabletop exercise

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    13% (5)
  • C
    75% (30)
  • D
    3% (1)
  • E
    3% (1)

Why each option

An internal assessment that must avoid impacting production systems and reduce costs points to passive, non-intrusive methods - configuration review and tabletop exercises fit both constraints.

AAgent-based vulnerability scan

An agent-based vulnerability scan actively probes systems and generates traffic that can trigger responses, consume resources, or crash services on production servers during business hours.

BBlack-box penetration testing

Black-box penetration testing uses aggressive, active exploitation techniques conducted by external parties, which both risks disrupting production systems and contradicts the goal of lowering costs.

CConfiguration reviewCorrect

Configuration review is a passive, read-only examination of device and system settings that generates no network traffic or active probing, making it safe to run during business hours without any risk to production servers. It is also entirely internal and low-cost, fitting the budget reduction goal while still covering specific devices and subnets.

DSocial engineering

Social engineering targets human behavior through deception and is unrelated to assessing specific devices or internal and external subnets for technical vulnerabilities.

EMalware sandboxing

Malware sandboxing is a technique for safely executing suspicious files to observe their behavior and is not a method for assessing network devices or subnets.

FTabletop exerciseCorrect

A tabletop exercise is a discussion-based activity where participants walk through scenarios without interacting with live systems, producing no network traffic or system load that could affect production, and it can be conducted entirely with internal staff at minimal cost.

Concept tested: Non-intrusive internal security assessment method selection

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#configuration review#tabletop exercise#internal assessment#vulnerability management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice