nerdexam
(ISC)2

CSSLP · Question #30

In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system?

The correct answer is B. Penetration test. A penetration test is a testing methodology where assessors use all available documentation and attempt to circumvent the security features of an information system without constraints.

Secure Software Testing

Question

In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system?

Options

  • AFull operational test
  • BPenetration test
  • CPaper test
  • DWalk-through test

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    90% (56)
  • C
    2% (1)
  • D
    5% (3)

Why each option

A penetration test is a testing methodology where assessors use all available documentation and attempt to circumvent the security features of an information system without constraints.

AFull operational test

A full operational test typically focuses on verifying the complete functionality and operational readiness of a system, not primarily on actively circumventing security features.

BPenetration testCorrect

A penetration test involves authorized individuals actively attempting to exploit vulnerabilities in a system, often mimicking real-world attack scenarios with varying levels of information about the target, to circumvent security features and assess the system's resilience against attacks.

CPaper test

A paper test, or desk check, involves reviewing security documentation and procedures without actual interaction with the live information system.

DWalk-through test

A walk-through test involves a team reviewing procedures and discussing hypothetical scenarios, similar to a paper test but often more interactive, without engaging with the live system.

Concept tested: Security testing methodologies - Penetration testing

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing

Topics

#Penetration testing#Security testing#Testing methodologies#White-box testing

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice