nerdexam
CompTIA

CAS-003 · Question #562

When implementing a penetration testing program, the Chief Information Security Officer (CISO) designates different organizational groups within the organization as having different…

The correct answer is B. the white team. In a structured penetration testing or cyber exercise framework, the white team serves as the administrative control group that operates from within the corporate environment. White team members have full situational awareness of the exercise, establish and enforce the rules of…

Enterprise Security Operations

Question

When implementing a penetration testing program, the Chief Information Security Officer (CISO) designates different organizational groups within the organization as having different responsibilities, attack vectors, and rules of engagement. First, the CISO designates a team to operate from within the corporate environment. This team is commonly referred to as:

Options

  • Athe blue team.
  • Bthe white team.
  • Cthe operations team.
  • Dthe read team.
  • Ethe development team.

How the community answered

(58 responses)
  • A
    3% (2)
  • B
    93% (54)
  • C
    2% (1)
  • E
    2% (1)

Explanation

In a structured penetration testing or cyber exercise framework, the white team serves as the administrative control group that operates from within the corporate environment. White team members have full situational awareness of the exercise, establish and enforce the rules of engagement, and act as referees or adjudicators to ensure the exercise is conducted safely and within agreed boundaries. The red team simulates external adversaries, the blue team defends the environment, and the purple team fosters collaboration between red and blue. The white team's position 'within the corporate environment' reflects their management and oversight role rather than an offensive or defensive one.

Topics

#penetration testing#white team#red team#rules of engagement

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice