nerdexam
PECB

LEAD-AUDITOR · Question #254

What is the objective of penetration testing in the risk assessment process?

The correct answer is B. To identify potential failures in the ICT protection schemes. The goal of penetration testing is to find vulnerabilities in networks, applications, and systems before attackers can exploit them. This aligns with ISO/IEC 27001:2022 Annex A Control A.8.16 (Monitoring Activities) and A.8.8 (Management of Technical Vulnerabilities).

Threats, Vulnerabilities, and Risk

Question

What is the objective of penetration testing in the risk assessment process?

Options

  • ATo conduct thorough code reviews
  • BTo identify potential failures in the ICT protection schemes
  • CTo physically inspect hardware components

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    86% (30)
  • C
    9% (3)

Explanation

The goal of penetration testing is to find vulnerabilities in networks, applications, and systems before attackers can exploit them. This aligns with ISO/IEC 27001:2022 Annex A Control A.8.16 (Monitoring Activities) and A.8.8 (Management of Technical Vulnerabilities).

Topics

#penetration testing#risk assessment#ICT protection#vulnerability identification

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice