nerdexam
Isaca

CISM · Question #295

Which of the following is the PRIMARY reason that an information security manager would contract with an external provider to perform penetration testing?

The correct answer is D. To obtain the full list of system vulnerabilities. The primary reason to contract an external provider for penetration testing is to obtain a comprehensive and unbiased identification of system vulnerabilities. External testers approach the environment with no prior knowledge, assumptions, or familiarity bias, which allows them t

Submitted by rachelw· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the PRIMARY reason that an information security manager would contract with an external provider to perform penetration testing?

Options

  • ATo obtain an independent view of vulnerabilities
  • BTo reduce the cost of testing
  • CTo train existing security staff
  • DTo obtain the full list of system vulnerabilities

How the community answered

(37 responses)
  • A
    16% (6)
  • B
    11% (4)
  • C
    3% (1)
  • D
    70% (26)

Explanation

The primary reason to contract an external provider for penetration testing is to obtain a comprehensive and unbiased identification of system vulnerabilities. External testers approach the environment with no prior knowledge, assumptions, or familiarity bias, which allows them to discover vulnerabilities that internal teams may have overlooked due to their proximity to the systems. Internal security staff may have blind spots from working closely with systems over time, or may unconsciously avoid testing certain areas. An external provider, starting from scratch as a real attacker would, provides the most thorough and objective enumeration of exploitable weaknesses. While independence (A) is a related benefit, the ultimate goal driving that independence is obtaining a more complete view of vulnerabilities that might otherwise go undetected.

Topics

#Penetration Testing#Vulnerability Assessment#Third-Party Management#Security Testing

Community Discussion

No community discussion yet for this question.

Full CISM Practice