nerdexam
GIAC

GCIH · Question #66

Which of the following tools can be used as penetration tools in the Information system auditing process? Each correct answer represents a complete solution. Choose two.

The correct answer is C. SARA D. Nessus. SARA and Nessus are dedicated vulnerability assessment tools used specifically in IS auditing and penetration testing engagements. Nmap and Snort serve different primary roles.

Reconnaissance, Scanning, and Enumeration

Question

Which of the following tools can be used as penetration tools in the Information system auditing process? Each correct answer represents a complete solution. Choose two.

Options

  • ANmap
  • BSnort
  • CSARA
  • DNessus

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    93% (27)

Why each option

SARA and Nessus are dedicated vulnerability assessment tools used specifically in IS auditing and penetration testing engagements. Nmap and Snort serve different primary roles.

ANmap

Nmap is a network discovery and port scanning tool used primarily in the reconnaissance phase, not a full penetration or vulnerability assessment tool for IS auditing.

BSnort

Snort is a network intrusion detection and prevention system (IDS/IPS) designed for defense and traffic analysis, not for offensive penetration testing.

CSARACorrect

SARA (Security Auditor's Research Assistant) is a network security analysis tool that identifies vulnerabilities in a target environment, making it a direct penetration/auditing tool.

DNessusCorrect

Nessus is an industry-standard vulnerability scanner that performs credentialed and uncredentialed scans to enumerate security weaknesses, widely used in formal IS auditing and penetration testing.

Concept tested: Vulnerability assessment tools for IS auditing

Source: https://www.tenable.com/products/nessus

Topics

#penetration testing tools#SARA#Nessus#IS auditing

Community Discussion

No community discussion yet for this question.

Full GCIH Practice