CISSP · Question #1147
An establish information technology (IT) consulting firm is considering acquiring a successful local startup. To gain a comprehensive understanding of the startup's security posture' which type of…
The correct answer is B. A penetration test. When an acquiring firm wants a comprehensive understanding of a target's actual security posture, a penetration test provides the most realistic, evidence-based assessment by actively probing defenses and uncovering exploitable vulnerabilities.
Question
Options
- AA security audit
- BA penetration test
- CA tabletop exercise
- DA security threat model
How the community answered
(26 responses)- A27% (7)
- B58% (15)
- C12% (3)
- D4% (1)
Why each option
When an acquiring firm wants a comprehensive understanding of a target's actual security posture, a penetration test provides the most realistic, evidence-based assessment by actively probing defenses and uncovering exploitable vulnerabilities.
A security audit evaluates compliance against a defined standard or policy framework, but does not actively test whether controls are effective or exploitable, making it less comprehensive for understanding actual security posture.
A penetration test actively simulates real-world attacks against the startup's systems, networks, and applications, producing concrete evidence of exploitable vulnerabilities and their potential business impact. This hands-on technical assessment reveals the true security posture-including misconfigurations, unpatched systems, and weak controls-that other assessment types may miss. For an acquisition scenario, this gives the acquiring firm objective, technical data to inform risk decisions and valuation.
A tabletop exercise is a discussion-based simulation of incident response scenarios that tests people and processes, not technical controls or actual vulnerabilities in systems.
A security threat model is a design-phase analysis that identifies potential threats against an architecture, but it does not validate whether those threats are currently exploitable or how well existing controls mitigate them.
Concept tested: Selecting appropriate security assessment type for acquisition due diligence
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.