nerdexam
(ISC)2

CGRC · Question #540

Which of the following NIST documents includes components for penetration testing? Response:

The correct answer is D. NIST SP 800-30. NIST Special Publication 800-30, "Guide for Conducting Risk Assessments," includes components for penetration testing by identifying it as a crucial method for discovering vulnerabilities. The document explains how information gathered from penetration tests serves as critical…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following NIST documents includes components for penetration testing? Response:

Options

  • ANIST SP 800-53
  • BNIST SP 800-26
  • CNIST SP 800-37
  • DNIST SP 800-30

How the community answered

(39 responses)
  • A
    3% (1)
  • C
    5% (2)
  • D
    92% (36)

Why each option

NIST Special Publication 800-30, "Guide for Conducting Risk Assessments," includes components for penetration testing by identifying it as a crucial method for discovering vulnerabilities. The document explains how information gathered from penetration tests serves as critical input for a comprehensive risk assessment, thus integrating it into the risk management process.

ANIST SP 800-53

NIST SP 800-53 defines "Penetration Testing" as a security control (CA-8), but SP 800-30 guides the use of such testing within risk assessment.

BNIST SP 800-26

NIST SP 800-26, "Security Self-Assessment Guide for Information Technology Systems," is an older, withdrawn document that does not specifically detail components for penetration testing in the context of current frameworks.

CNIST SP 800-37

NIST SP 800-37, the Risk Management Framework guide, refers to penetration testing as an assessment method, but SP 800-30 focuses on its role in identifying risks.

DNIST SP 800-30Correct

NIST SP 800-30, "Guide for Conducting Risk Assessments," explicitly recognizes penetration testing as a method for identifying vulnerabilities, which provides essential input for conducting effective risk assessments.

Concept tested: NIST documents and penetration testing's role

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#NIST Special Publications#Penetration Testing#Risk Assessment#Vulnerability Identification

Community Discussion

No community discussion yet for this question.

Full CGRC Practice