CAS-003 · Question #810
The Chief information Security Officer (CISO) of a small locate bank has a compliance requirement that a third-party penetration test of the core banking application must be conducted annually…
The correct answer is C. Red-team hunting. NOTE: The marked answer (C - Red-team hunting) is likely incorrect. Red-team engagements are among the MOST resource-intensive security assessments, involving comprehensive adversarial simulation across people, processes, and technology. For a compliance requirement to test a…
Question
The Chief information Security Officer (CISO) of a small locate bank has a compliance requirement that a third-party penetration test of the core banking application must be conducted annually. Which of the following services would fulfill the compliance requirement with the LOWEST resource usage?
Options
- ABlack-box testing
- BGray-box testing
- CRed-team hunting
- DWhite-box testing
- EBlue-learn exercises
How the community answered
(27 responses)- A4% (1)
- B7% (2)
- C70% (19)
- D15% (4)
- E4% (1)
Explanation
NOTE: The marked answer (C - Red-team hunting) is likely incorrect. Red-team engagements are among the MOST resource-intensive security assessments, involving comprehensive adversarial simulation across people, processes, and technology. For a compliance requirement to test a specific application annually with the LOWEST resource usage, white-box testing (D) is the correct answer. White-box testing provides the tester with full access to documentation, architecture diagrams, and source code - eliminating time spent on reconnaissance and allowing the tester to focus directly on vulnerabilities. This approach requires less time and fewer billable hours from the third party, minimizing resource consumption while still fulfilling the compliance requirement.
Topics
Community Discussion
No community discussion yet for this question.