GPEN · Question #455
As pan or a penetration lest, your team is tasked with discovering vulnerabilities that could be exploited from an inside threat vector. Which of the following activities fall within that scope?
The correct answer is C. B and D. Inside threat testing scope covers activities a malicious or compromised internal user could perform, excluding external or perimeter-facing attack vectors.
Question
As pan or a penetration lest, your team is tasked with discovering vulnerabilities that could be exploited from an inside threat vector. Which of the following activities fall within that scope?
Options
- AB, C, and D
- BA, B. and D
- CB and D
- DA and D
How the community answered
(40 responses)- A8% (3)
- B3% (1)
- C80% (32)
- D10% (4)
Why each option
Inside threat testing scope covers activities a malicious or compromised internal user could perform, excluding external or perimeter-facing attack vectors.
Including all four options would add activities that target external attack surfaces, which are outside the defined scope of an inside threat assessment.
Including option A alongside B and D introduces an activity representing an external attack vector that is not relevant to simulating an inside threat.
Options B and D represent activities consistent with an inside threat vector - such as internal privilege escalation, lateral movement, or abuse of internal resources - which are the actions a rogue insider or compromised internal account could take. Option A likely involves an external or perimeter-based attack technique that falls outside the defined inside threat scope, making it the excluded item.
Including only A and D omits option B, which is an activity that falls squarely within inside threat simulation scope.
Concept tested: Inside threat penetration testing scope identification
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.