GCIH · Question #66
Which of the following tools can be used as penetration tools in the Information system auditing process? Each correct answer represents a complete solution. Choose two.
The correct answer is C. SARA D. Nessus. SARA and Nessus are dedicated vulnerability assessment tools used specifically in IS auditing and penetration testing engagements. Nmap and Snort serve different primary roles.
Question
Which of the following tools can be used as penetration tools in the Information system auditing process? Each correct answer represents a complete solution. Choose two.
Options
- ANmap
- BSnort
- CSARA
- DNessus
How the community answered
(29 responses)- A3% (1)
- B3% (1)
- C93% (27)
Why each option
SARA and Nessus are dedicated vulnerability assessment tools used specifically in IS auditing and penetration testing engagements. Nmap and Snort serve different primary roles.
Nmap is a network discovery and port scanning tool used primarily in the reconnaissance phase, not a full penetration or vulnerability assessment tool for IS auditing.
Snort is a network intrusion detection and prevention system (IDS/IPS) designed for defense and traffic analysis, not for offensive penetration testing.
SARA (Security Auditor's Research Assistant) is a network security analysis tool that identifies vulnerabilities in a target environment, making it a direct penetration/auditing tool.
Nessus is an industry-standard vulnerability scanner that performs credentialed and uncredentialed scans to enumerate security weaknesses, widely used in formal IS auditing and penetration testing.
Concept tested: Vulnerability assessment tools for IS auditing
Source: https://www.tenable.com/products/nessus
Topics
Community Discussion
No community discussion yet for this question.