CGRC · Question #482
In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system?…
The correct answer is C. Penetration test. This question describes a testing methodology where assessors have full knowledge, no constraints, and actively try to bypass security features, which is characteristic of a penetration test.
Question
In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system? Response:
Options
- AFull operational test
- BWalk-through test
- CPenetration test
- DPaper test
How the community answered
(21 responses)- A5% (1)
- C86% (18)
- D10% (2)
Why each option
This question describes a testing methodology where assessors have full knowledge, no constraints, and actively try to bypass security features, which is characteristic of a penetration test.
A full operational test typically refers to testing the complete system's functionality and performance under operational conditions, not primarily focused on circumventing security.
A walk-through test usually involves reviewing documentation or processes step-by-step for understanding or compliance, not actively attempting to exploit security weaknesses.
A penetration test, also known as a pen test, is a simulated cyberattack against an information system to check for exploitable vulnerabilities. Assessors in a penetration test often operate with full knowledge of the system (white-box testing, aligning with 'all available documentation') and no constraints, actively attempting to circumvent security controls to identify real-world attack paths.
A paper test (or desktop review) involves reviewing documentation without interacting with the live system, thus not involving attempts to circumvent security features.
Concept tested: Penetration testing methodology
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Topics
Community Discussion
No community discussion yet for this question.