CISM · Question #295
Which of the following is the PRIMARY reason that an information security manager would contract with an external provider to perform penetration testing?
The correct answer is D. To obtain the full list of system vulnerabilities. The primary reason to contract an external provider for penetration testing is to obtain a comprehensive and unbiased identification of system vulnerabilities. External testers approach the environment with no prior knowledge, assumptions, or familiarity bias, which allows them t
Question
Which of the following is the PRIMARY reason that an information security manager would contract with an external provider to perform penetration testing?
Options
- ATo obtain an independent view of vulnerabilities
- BTo reduce the cost of testing
- CTo train existing security staff
- DTo obtain the full list of system vulnerabilities
How the community answered
(37 responses)- A16% (6)
- B11% (4)
- C3% (1)
- D70% (26)
Explanation
The primary reason to contract an external provider for penetration testing is to obtain a comprehensive and unbiased identification of system vulnerabilities. External testers approach the environment with no prior knowledge, assumptions, or familiarity bias, which allows them to discover vulnerabilities that internal teams may have overlooked due to their proximity to the systems. Internal security staff may have blind spots from working closely with systems over time, or may unconsciously avoid testing certain areas. An external provider, starting from scratch as a real attacker would, provides the most thorough and objective enumeration of exploitable weaknesses. While independence (A) is a related benefit, the ultimate goal driving that independence is obtaining a more complete view of vulnerabilities that might otherwise go undetected.
Topics
Community Discussion
No community discussion yet for this question.