CSSLP · Question #229
Which of the following test methods has the objective to test the IT system from the viewpoint of a threat-source and to identify potential failures in the IT system protection schemes?
The correct answer is B. Penetration testing. Penetration testing is a security assessment method that simulates real-world attacks from a threat-source's perspective to uncover vulnerabilities and identify weaknesses in an IT system's protection schemes. This method provides a realistic evaluation of a system's resilience a
Question
Which of the following test methods has the objective to test the IT system from the viewpoint of a threat-source and to identify potential failures in the IT system protection schemes?
Options
- ASecurity Test and Evaluation (ST&E)
- BPenetration testing
- CAutomated vulnerability scanning tool
- DOn-site interviews
How the community answered
(21 responses)- B90% (19)
- C5% (1)
- D5% (1)
Why each option
Penetration testing is a security assessment method that simulates real-world attacks from a threat-source's perspective to uncover vulnerabilities and identify weaknesses in an IT system's protection schemes. This method provides a realistic evaluation of a system's resilience against malicious activities.
Security Test and Evaluation (ST&E) is a broader process of systematically examining and testing a system's security features and controls to ensure they meet specified security requirements, but it's not exclusively from a threat-source's perspective.
Penetration testing (pen testing) is a simulated cyberattack against your computer system to check for exploitable vulnerabilities. This method is specifically designed to test an IT system from the viewpoint of a potential attacker (a threat-source) to identify weaknesses, misconfigurations, and potential failures in the system's security controls and protection schemes. The objective is to proactively discover how an attacker could breach the system and exploit its vulnerabilities, allowing organizations to remediate these issues before they are exploited in a real attack.
Automated vulnerability scanning tools identify known vulnerabilities in systems by scanning for signatures or common misconfigurations, but they do not actively exploit vulnerabilities or simulate a threat-source's thought process or methodology.
On-site interviews are a qualitative method used to gather information from personnel about security policies, procedures, and perceptions, but they do not directly test technical system protection schemes from an adversarial perspective.
Concept tested: Security testing - Penetration testing
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.