PT0-001 · Question #251
A security team is switching firewall vendors. The director of security wants to scope a penetration test to satisfy requirements to perform the test after major architectural changes. Which of the…
The correct answer is D. Focus on an objective-based approach to assess network assets with a red team. After major architectural changes like a firewall replacement, an objective-based red team engagement provides the most realistic and comprehensive assessment of the new security posture.
Question
A security team is switching firewall vendors. The director of security wants to scope a penetration test to satisfy requirements to perform the test after major architectural changes. Which of the following is the BEST way to approach the project?
Options
- ADesign a penetration test approach, focusing on publicly released firewall DoS vulnerabilities.
- BReview the firewall configuration, followed by a targeted attack by a read team.
- CPerform a discovery scan to identify changes in the network.
- DFocus on an objective-based approach to assess network assets with a red team.
How the community answered
(40 responses)- A15% (6)
- B8% (3)
- C5% (2)
- D73% (29)
Why each option
After major architectural changes like a firewall replacement, an objective-based red team engagement provides the most realistic and comprehensive assessment of the new security posture.
Focusing only on publicly released DoS vulnerabilities for the new vendor is too narrow and does not assess whether the overall network architecture is secure after the change.
A configuration review followed by a targeted attack is limited in scope and does not simulate realistic threat scenarios across the broader network that the new architecture affects.
A discovery scan identifies what changed in the network topology but provides no assessment of whether those changes are exploitable or whether security objectives can be bypassed.
An objective-based approach instructs the red team to achieve realistic adversarial goals (e.g., reach a database server, exfiltrate data) rather than merely scanning for known CVEs. This validates whether the new firewall architecture and surrounding controls actually prevent an attacker from accomplishing meaningful objectives. It covers the full attack surface introduced by the architectural change, not just the firewall device in isolation.
Concept tested: Objective-based red team scoping after architectural change
Source: https://www.nist.gov/system/files/documents/2021/02/05/NIST-SP-800-115-2008.pdf
Topics
Community Discussion
No community discussion yet for this question.