nerdexam
(ISC)2

CSSLP · Question #234

Which of the following processes will you involve to perform the active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known and/o

The correct answer is A. Penetration testing. Penetration testing is the process used to actively analyze a system for vulnerabilities arising from misconfigurations, known or unknown flaws, or operational weaknesses. It involves simulating attacks to identify exploitable weaknesses.

Secure Software Testing

Question

Which of the following processes will you involve to perform the active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known and/or unknown hardware or software flaws, or operational weaknesses in process or technical countermeasures?

Options

  • APenetration testing
  • BBaselining
  • CRisk analysis
  • DCompliance checking

How the community answered

(45 responses)
  • A
    93% (42)
  • B
    2% (1)
  • D
    4% (2)

Why each option

Penetration testing is the process used to actively analyze a system for vulnerabilities arising from misconfigurations, known or unknown flaws, or operational weaknesses. It involves simulating attacks to identify exploitable weaknesses.

APenetration testingCorrect

Penetration testing involves actively simulating real-world attacks against a system to identify and exploit vulnerabilities that could arise from poor configuration, software/hardware flaws (both known and unknown), or operational weaknesses. This hands-on process goes beyond simply scanning, aiming to discover if identified weaknesses are actually exploitable and what impact a successful exploit would have. The objective is to proactively find holes in security defenses before malicious actors do.

BBaselining

Baselining involves establishing a known, secure configuration or state for a system, which is a starting point for security but not an active analysis process for vulnerabilities.

CRisk analysis

Risk analysis is the process of identifying, analyzing, and evaluating risks to an organization's assets, focusing on understanding potential threats and their impact, rather than actively performing technical analysis on a system's vulnerabilities.

DCompliance checking

Compliance checking involves verifying that a system or process adheres to specific regulatory requirements, industry standards, or internal policies, but it does not typically involve active exploitation or discovery of unknown technical vulnerabilities.

Concept tested: Security assessment - Penetration testing

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#Penetration testing#Vulnerability assessment#Security testing#System configuration security

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice