nerdexam
(ISC)2

CSSLP · Question #229

Which of the following test methods has the objective to test the IT system from the viewpoint of a threat-source and to identify potential failures in the IT system protection schemes?

The correct answer is B. Penetration testing. Penetration testing is a security assessment method that simulates real-world attacks from a threat-source's perspective to uncover vulnerabilities and identify weaknesses in an IT system's protection schemes. This method provides a realistic evaluation of a system's resilience a

Secure Software Testing

Question

Which of the following test methods has the objective to test the IT system from the viewpoint of a threat-source and to identify potential failures in the IT system protection schemes?

Options

  • ASecurity Test and Evaluation (ST&E)
  • BPenetration testing
  • CAutomated vulnerability scanning tool
  • DOn-site interviews

How the community answered

(21 responses)
  • B
    90% (19)
  • C
    5% (1)
  • D
    5% (1)

Why each option

Penetration testing is a security assessment method that simulates real-world attacks from a threat-source's perspective to uncover vulnerabilities and identify weaknesses in an IT system's protection schemes. This method provides a realistic evaluation of a system's resilience against malicious activities.

ASecurity Test and Evaluation (ST&E)

Security Test and Evaluation (ST&E) is a broader process of systematically examining and testing a system's security features and controls to ensure they meet specified security requirements, but it's not exclusively from a threat-source's perspective.

BPenetration testingCorrect

Penetration testing (pen testing) is a simulated cyberattack against your computer system to check for exploitable vulnerabilities. This method is specifically designed to test an IT system from the viewpoint of a potential attacker (a threat-source) to identify weaknesses, misconfigurations, and potential failures in the system's security controls and protection schemes. The objective is to proactively discover how an attacker could breach the system and exploit its vulnerabilities, allowing organizations to remediate these issues before they are exploited in a real attack.

CAutomated vulnerability scanning tool

Automated vulnerability scanning tools identify known vulnerabilities in systems by scanning for signatures or common misconfigurations, but they do not actively exploit vulnerabilities or simulate a threat-source's thought process or methodology.

DOn-site interviews

On-site interviews are a qualitative method used to gather information from personnel about security policies, procedures, and perceptions, but they do not directly test technical system protection schemes from an adversarial perspective.

Concept tested: Security testing - Penetration testing

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#Penetration Testing#Security Testing#Threat Simulation#Vulnerability Assessment

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice