CV0-003 · Question #159
A college has implemented a private cloud for students and faculty. The college is required by their accrediting body to ensure that the cloud meets certain confidentiality and privacy requirements…
The correct answer is A. A vulnerability assessment should be conducted by the MIS department. A vulnerability assessment is less intrusive than a penetration test, and using the internal MIS department satisfies separation of duties from the cloud operations staff while minimizing organizational disruption.
Question
A college has implemented a private cloud for students and faculty. The college is required by their accrediting body to ensure that the cloud meets certain confidentiality and privacy requirements. Which of the following represents the LEAST intrusive testing method for the college to use, while ensuring separation of duties during the testing?
Options
- AA vulnerability assessment should be conducted by the MIS department.
- BA penetration test should be conducted by an accredited third party.
- CA penetration test should be conducted by the MIS department.
- DA vulnerability assessment should be conducted by an accredited third party.
How the community answered
(69 responses)- A70% (48)
- B6% (4)
- C9% (6)
- D16% (11)
Why each option
A vulnerability assessment is less intrusive than a penetration test, and using the internal MIS department satisfies separation of duties from the cloud operations staff while minimizing organizational disruption.
A vulnerability assessment passively scans for weaknesses without actively exploiting them, making it the least intrusive testing method available. The MIS department, as a distinct internal governance body separate from the team that operates and administers the private cloud, provides the required separation of duties without the added cost and operational intrusion of engaging an external third party.
A penetration test by a third party satisfies separation of duties but is more intrusive because it actively attempts to exploit discovered vulnerabilities, increasing risk and operational impact.
A penetration test is more intrusive due to active exploitation, and if the MIS department also administers the cloud infrastructure, having them conduct the test would violate separation of duties.
An accredited third party provides strong separation of duties, but bringing in an external organization is more organizationally and operationally intrusive than leveraging an internal department.
Concept tested: Vulnerability assessment vs penetration test - least intrusive with separation of duties
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.