nerdexam
CompTIA

CV0-002 · Question #518

A company has developed a SaaS product for the financial services industry. The Chief Executive Officer (CEO) of the SaaS company has engaged an independent third party to run tests against its platfo

The correct answer is A. Penetration testing. An independent third party engaged by a CEO to test a SaaS product for the financial services industry would most likely perform penetration testing to validate its security posture.

Security

Question

A company has developed a SaaS product for the financial services industry. The Chief Executive Officer (CEO) of the SaaS company has engaged an independent third party to run tests against its platform. Which of the following is the MOST likely test the third party has been engaged to perform?

Options

  • APenetration testing
  • BLoad testing
  • CVulnerability testing
  • DFunctionality testing

How the community answered

(62 responses)
  • A
    74% (46)
  • B
    6% (4)
  • C
    16% (10)
  • D
    3% (2)

Why each option

An independent third party engaged by a CEO to test a SaaS product for the financial services industry would most likely perform penetration testing to validate its security posture.

APenetration testingCorrect

For a SaaS product in the highly regulated financial services industry, security is paramount; an independent third party is most likely engaged to perform penetration testing, which actively attempts to exploit vulnerabilities to simulate real-world attacks and provide a comprehensive assessment of the platform's security defenses and compliance readiness.

BLoad testing

Load testing focuses on performance and scalability under stress, not the primary security concerns critical for financial services.

CVulnerability testing

While vulnerability testing identifies weaknesses, penetration testing goes further by attempting to exploit them, offering a more complete security validation often sought from independent third parties.

DFunctionality testing

Functionality testing verifies if the application's features work as intended, which is typically an internal quality assurance task rather than the primary reason to engage an independent security firm for a financial product.

Concept tested: Security testing types (penetration testing)

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing

Topics

#Penetration Testing#SaaS Security#Third-Party Audit#Financial Services Security

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice