CAS-003 · Question #609
A Chief Information Security Officer (CISO) is running a test to evaluate the security of the corporate network and attached devices. Which of the following components should be executed by an…
The correct answer is A. Penetration tests. Penetration tests are best conducted by outside (third-party) vendors because external testers bring an unbiased, independent perspective and simulate a real-world attacker who has no prior knowledge of the internal environment. This removes conflicts of interest and insider…
Question
A Chief Information Security Officer (CISO) is running a test to evaluate the security of the corporate network and attached devices. Which of the following components should be executed by an outside vendor?
Options
- APenetration tests
- BVulnerability assessment
- CTabletop exercises
- DBlue-team operations
How the community answered
(23 responses)- A87% (20)
- B9% (2)
- D4% (1)
Explanation
Penetration tests are best conducted by outside (third-party) vendors because external testers bring an unbiased, independent perspective and simulate a real-world attacker who has no prior knowledge of the internal environment. This removes conflicts of interest and insider bias. Vulnerability assessments (B) are often performed internally. Tabletop exercises (C) are discussion-based simulations that don't require external parties. Blue-team operations (D) are defensive activities performed by internal security staff. The independence and objectivity of a third party is specifically why penetration testing is the correct answer here.
Topics
Community Discussion
No community discussion yet for this question.