nerdexam
EC-Council

EC0-350 · Question #265

When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is

The correct answer is D. OSSTMM addresses controls and OWASP does not. See the full explanation below for the reasoning.

Question

When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is

Options

  • AOWASP is for web applications and OSSTMM does not include web applications.
  • BOSSTMM is gray box testing and OWASP is black box testing.
  • COWASP addresses controls and OSSTMM does not.
  • DOSSTMM addresses controls and OWASP does not.

How the community answered

(26 responses)
  • A
    12% (3)
  • B
    4% (1)
  • C
    4% (1)
  • D
    81% (21)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice