GPEN · Question #321
In which of the following security tests does the security testing team simulate as an employee or other person with an authorized connection to the organization's network?
The correct answer is D. Local network. A local network test simulates an insider threat by having the tester operate as an employee or authorized user with direct access to the internal network.
Question
In which of the following security tests does the security testing team simulate as an employee or other person with an authorized connection to the organization's network?
Options
- ARemote dial-up network
- BStolen equipment
- CRemote network
- DLocal network
How the community answered
(40 responses)- A10% (4)
- B5% (2)
- C3% (1)
- D83% (33)
Why each option
A local network test simulates an insider threat by having the tester operate as an employee or authorized user with direct access to the internal network.
Remote dial-up testing simulates an attacker connecting via modem or dial-up lines from outside the organization, not an insider with authorized local access.
Stolen equipment testing evaluates risks from physical theft of devices such as laptops, focusing on data-at-rest protections rather than simulating an authorized network user.
Remote network testing simulates an external attacker connecting over the internet or a WAN link, which is the opposite of an insider scenario.
In a local network security test, the tester is physically or logically positioned inside the network perimeter, mimicking an employee or contractor who already has authorized connectivity. This tests internal controls, lateral movement possibilities, and trust boundaries that would be exploited by a malicious insider or a compromised internal account.
Concept tested: Insider threat simulation in penetration testing
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.