ISO-IEC-27001-LEAD-AUDITOR · Question #297
What is the objective of penetration testing in the risk assessment process?
The correct answer is B. To identify potential failures in the ICT protection schemes. Penetration testing (pen testing) is a simulated cyberattack used to assess security weaknesses in an ICT system. Identifying failures in ICT protection schemes ?Correct answer. The goal of penetration testing is to find vulnerabilities in networks, applications, and systems…
Question
What is the objective of penetration testing in the risk assessment process?
Options
- ATo conduct thorough code reviews
- BTo identify potential failures in the ICT protection schemes
- CTo physically inspect hardware components
How the community answered
(21 responses)- A5% (1)
- B90% (19)
- C5% (1)
Explanation
Penetration testing (pen testing) is a simulated cyberattack used to assess security weaknesses in an ICT system. Identifying failures in ICT protection schemes ?Correct answer. The goal of penetration testing is to find vulnerabilities in networks, applications, and systems before attackers can exploit them. This aligns with ISO/IEC 27001:2022 Annex A Control A.8.16 (Monitoring Activities) and A.8.8 (Management of Technical Vulnerabilities).
Topics
Community Discussion
No community discussion yet for this question.