nerdexam
Isaca

CISM · Question #660

The PRIMARY reason to conduct application security and penetration testing for internet-facing applications is to:

The correct answer is A. verify that applications are not susceptible to external attacks. Internet-facing applications are exposed to the widest possible threat surface. The primary purpose of application security and penetration testing in this context is to validate that the application can withstand external attack attempts - confirming that known vulnerabilities a

Submitted by tunde_lagos· Apr 18, 2026Information Security Risk Management

Question

The PRIMARY reason to conduct application security and penetration testing for internet-facing applications is to:

Options

  • Averify that applications are not susceptible to external attacks
  • Bdetect runtime vulnerabilities within applications
  • Cdetermine web application firewall (WAF) configurations
  • Dtest the effectiveness of the incident response team

How the community answered

(20 responses)
  • A
    95% (19)
  • B
    5% (1)

Explanation

Internet-facing applications are exposed to the widest possible threat surface. The primary purpose of application security and penetration testing in this context is to validate that the application can withstand external attack attempts - confirming that known vulnerabilities and attack vectors have been addressed. While penetration testing may reveal runtime vulnerabilities (B), influence WAF tuning (C), or test IR team readiness (D), none of these is the primary objective. The core goal is assurance against external exploitation.

Topics

#Application Security#Penetration Testing#Vulnerability Assessment#External Threats

Community Discussion

No community discussion yet for this question.

Full CISM Practice