CSSLP · Question #234
Which of the following processes will you involve to perform the active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known and/o
The correct answer is A. Penetration testing. Penetration testing is the process used to actively analyze a system for vulnerabilities arising from misconfigurations, known or unknown flaws, or operational weaknesses. It involves simulating attacks to identify exploitable weaknesses.
Question
Which of the following processes will you involve to perform the active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known and/or unknown hardware or software flaws, or operational weaknesses in process or technical countermeasures?
Options
- APenetration testing
- BBaselining
- CRisk analysis
- DCompliance checking
How the community answered
(45 responses)- A93% (42)
- B2% (1)
- D4% (2)
Why each option
Penetration testing is the process used to actively analyze a system for vulnerabilities arising from misconfigurations, known or unknown flaws, or operational weaknesses. It involves simulating attacks to identify exploitable weaknesses.
Penetration testing involves actively simulating real-world attacks against a system to identify and exploit vulnerabilities that could arise from poor configuration, software/hardware flaws (both known and unknown), or operational weaknesses. This hands-on process goes beyond simply scanning, aiming to discover if identified weaknesses are actually exploitable and what impact a successful exploit would have. The objective is to proactively find holes in security defenses before malicious actors do.
Baselining involves establishing a known, secure configuration or state for a system, which is a starting point for security but not an active analysis process for vulnerabilities.
Risk analysis is the process of identifying, analyzing, and evaluating risks to an organization's assets, focusing on understanding potential threats and their impact, rather than actively performing technical analysis on a system's vulnerabilities.
Compliance checking involves verifying that a system or process adheres to specific regulatory requirements, industry standards, or internal policies, but it does not typically involve active exploitation or discovery of unknown technical vulnerabilities.
Concept tested: Security assessment - Penetration testing
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.