nerdexam
GIAC

GPEN · Question #411

Your company has decided that the risk of performing a penetration test Is too great. You would like to figure out other ways to find vulnerabilities on their systems, which of the following is MOST…

The correct answer is A. Network scope Analysis. When active penetration testing carries too much operational risk, security teams need passive alternatives to surface vulnerabilities. Network scope analysis is the most direct substitute for understanding exposure without active exploitation.

Penetration Testing Foundations & Reconnaissance

Question

Your company has decided that the risk of performing a penetration test Is too great. You would like to figure out other ways to find vulnerabilities on their systems, which of the following is MOST likely to be a valid alternative?

Options

  • ANetwork scope Analysis
  • BBaseline Data Reviews
  • CPatch Policy Review
  • DConfiguration Reviews

How the community answered

(64 responses)
  • A
    72% (46)
  • B
    5% (3)
  • C
    6% (4)
  • D
    17% (11)

Why each option

When active penetration testing carries too much operational risk, security teams need passive alternatives to surface vulnerabilities. Network scope analysis is the most direct substitute for understanding exposure without active exploitation.

ANetwork scope AnalysisCorrect

Network scope analysis passively inventories all systems, services, and open ports visible on the network to map the attack surface without triggering exploits or disrupting operations. It reveals misconfigurations, unnecessary service exposures, and network segmentation gaps in a way that closely mirrors pen test reconnaissance but without the execution risk that prompted the alternative search.

BBaseline Data Reviews

Baseline data reviews compare current system state to a prior snapshot to detect drift, but they do not proactively surface unknown vulnerabilities or new misconfigurations the way an active assessment would.

CPatch Policy Review

Patch policy review evaluates the organization's process for applying updates and identifies procedural gaps, but does not directly enumerate specific technical vulnerabilities present on live systems.

DConfiguration Reviews

Configuration reviews check systems against benchmarks such as CIS or DISA STIG and are a valid technique, but the question asks for the alternative most likely to surface network-wide vulnerabilities broadly, which network scope analysis addresses more completely.

Concept tested: Passive vulnerability assessment alternatives to active penetration testing

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#penetration testing alternatives#risk assessment#vulnerability management#scope

Community Discussion

No community discussion yet for this question.

Full GPEN Practice