nerdexam
(ISC)2

CSSLP · Question #203

Maria has been recently appointed as a Network Administrator in Gentech Inc. She has been tasked to perform network security testing to find out the vulnerabilities and shortcomings of the present net

The correct answer is C. Black-box testing. To find vulnerabilities and shortcomings in the network infrastructure from an external attacker's perspective, Maria should use black-box testing. This approach simulates an external attack without prior knowledge of the internal system.

Secure Software Testing

Question

Maria has been recently appointed as a Network Administrator in Gentech Inc. She has been tasked to perform network security testing to find out the vulnerabilities and shortcomings of the present network infrastructure. Which of the following testing approaches will she apply to accomplish this task?

Options

  • AGray-box testing
  • BWhite-box testing
  • CBlack-box testing
  • DUnit testing

How the community answered

(21 responses)
  • B
    5% (1)
  • C
    90% (19)
  • D
    5% (1)

Why each option

To find vulnerabilities and shortcomings in the network infrastructure from an external attacker's perspective, Maria should use black-box testing. This approach simulates an external attack without prior knowledge of the internal system.

AGray-box testing

Gray-box testing involves having some limited knowledge of the internal system, which is not the primary goal when simulating an external attacker's discovery of vulnerabilities.

BWhite-box testing

White-box testing involves complete knowledge of the system's internal structure and code, which is used for in-depth code review or specific vulnerability checks, not for discovering unknown vulnerabilities from an external perspective.

CBlack-box testingCorrect

Black-box testing involves evaluating a system's security from an external perspective, with no prior knowledge of its internal structure, code, or architecture. This approach is ideal for simulating how an unauthorized external attacker would attempt to find vulnerabilities and exploit them in a network infrastructure.

DUnit testing

Unit testing is a software development practice used to test individual components or units of a program, not an approach for network security vulnerability assessment.

Concept tested: Network security testing methodologies

Source: https://learn.microsoft.com/en-us/azure/security/benchmarks/security-controls-v2-dev-sec-ops#dv-1-create-and-manage-a-secure-software-development-lifecycle

Topics

#Black-box testing#Security testing#Vulnerability assessment

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice