nerdexam
(ISC)2

CISSP · Question #1063

When assessing web vulnerabilities, how can navigating the dark web add value to a penetration test?

The correct answer is B. Information may be found on related breaches and hacking. The dark web is often a source of illicit information, including data dumps, hacking tools, exploit kits, and discussions about known vulnerabilities, breaches, and cyberattacks. By navigating the dark web, penetration testers can gain insights into: Exploits that attackers are…

Submitted by brentm· Mar 5, 2026Security Assessment and Testing

Question

When assessing web vulnerabilities, how can navigating the dark web add value to a penetration test?

Options

  • AThe actual origin and tools used for the test can be hidden.
  • BInformation may be found on related breaches and hacking.
  • CVulnerabilities can be tested without impact on the tested environment.
  • DInformation may be found on hidden vendor patches.

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    78% (21)
  • C
    4% (1)
  • D
    15% (4)

Explanation

The dark web is often a source of illicit information, including data dumps, hacking tools, exploit kits, and discussions about known vulnerabilities, breaches, and cyberattacks. By navigating the dark web, penetration testers can gain insights into: Exploits that attackers are using against systems, which may help in identifying vulnerabilities within the target environment. Credential dumps and other sensitive data that may indicate a breach in the target organization or its related entities. Discussion threads where attackers or malicious actors share techniques or vulnerabilities they are exploiting, which could be relevant to the system being tested.

Topics

#penetration testing#dark web intelligence#vulnerability assessment#threat intelligence

Community Discussion

No community discussion yet for this question.

Full CISSP Practice