GPEN · Question #411
Your company has decided that the risk of performing a penetration test Is too great. You would like to figure out other ways to find vulnerabilities on their systems, which of the following is MOST…
The correct answer is A. Network scope Analysis. When active penetration testing carries too much operational risk, security teams need passive alternatives to surface vulnerabilities. Network scope analysis is the most direct substitute for understanding exposure without active exploitation.
Question
Your company has decided that the risk of performing a penetration test Is too great. You would like to figure out other ways to find vulnerabilities on their systems, which of the following is MOST likely to be a valid alternative?
Options
- ANetwork scope Analysis
- BBaseline Data Reviews
- CPatch Policy Review
- DConfiguration Reviews
How the community answered
(64 responses)- A72% (46)
- B5% (3)
- C6% (4)
- D17% (11)
Why each option
When active penetration testing carries too much operational risk, security teams need passive alternatives to surface vulnerabilities. Network scope analysis is the most direct substitute for understanding exposure without active exploitation.
Network scope analysis passively inventories all systems, services, and open ports visible on the network to map the attack surface without triggering exploits or disrupting operations. It reveals misconfigurations, unnecessary service exposures, and network segmentation gaps in a way that closely mirrors pen test reconnaissance but without the execution risk that prompted the alternative search.
Baseline data reviews compare current system state to a prior snapshot to detect drift, but they do not proactively surface unknown vulnerabilities or new misconfigurations the way an active assessment would.
Patch policy review evaluates the organization's process for applying updates and identifies procedural gaps, but does not directly enumerate specific technical vulnerabilities present on live systems.
Configuration reviews check systems against benchmarks such as CIS or DISA STIG and are a valid technique, but the question asks for the alternative most likely to surface network-wide vulnerabilities broadly, which network scope analysis addresses more completely.
Concept tested: Passive vulnerability assessment alternatives to active penetration testing
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.