nerdexam
CompTIA

CAS-003 · Question #609

A Chief Information Security Officer (CISO) is running a test to evaluate the security of the corporate network and attached devices. Which of the following components should be executed by an…

The correct answer is A. Penetration tests. Penetration tests are best conducted by outside (third-party) vendors because external testers bring an unbiased, independent perspective and simulate a real-world attacker who has no prior knowledge of the internal environment. This removes conflicts of interest and insider…

Risk Management

Question

A Chief Information Security Officer (CISO) is running a test to evaluate the security of the corporate network and attached devices. Which of the following components should be executed by an outside vendor?

Options

  • APenetration tests
  • BVulnerability assessment
  • CTabletop exercises
  • DBlue-team operations

How the community answered

(23 responses)
  • A
    87% (20)
  • B
    9% (2)
  • D
    4% (1)

Explanation

Penetration tests are best conducted by outside (third-party) vendors because external testers bring an unbiased, independent perspective and simulate a real-world attacker who has no prior knowledge of the internal environment. This removes conflicts of interest and insider bias. Vulnerability assessments (B) are often performed internally. Tabletop exercises (C) are discussion-based simulations that don't require external parties. Blue-team operations (D) are defensive activities performed by internal security staff. The independence and objectivity of a third party is specifically why penetration testing is the correct answer here.

Topics

#penetration testing#third-party assessment#independent verification#security testing

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice