nerdexam
CompTIA

PT0-002 · Question #133

A compliance-based penetration test is primarily concerned with:

The correct answer is C. determining the efficacy of a specific set of security standards. A compliance-based penetration test's main objective is to assess an organization's adherence to and the effectiveness of controls related to specific security standards or regulations.

Planning and Scoping

Question

A compliance-based penetration test is primarily concerned with:

Options

  • Aobtaining PII from the protected network.
  • Bbypassing protection on edge devices.
  • Cdetermining the efficacy of a specific set of security standards.
  • Dobtaining specific information from the protected network.

How the community answered

(22 responses)
  • A
    9% (2)
  • C
    86% (19)
  • D
    5% (1)

Why each option

A compliance-based penetration test's main objective is to assess an organization's adherence to and the effectiveness of controls related to specific security standards or regulations.

Aobtaining PII from the protected network.

While a compliance test might involve attempting to access PII, its primary concern is not the acquisition of PII itself, but rather assessing whether the controls protecting such data comply with relevant standards.

Bbypassing protection on edge devices.

Bypassing protections on edge devices is a potential technique within a penetration test, but it is not the overarching primary concern of a compliance-based test, which focuses on adherence to standards across the scope.

Cdetermining the efficacy of a specific set of security standards.Correct

A compliance-based penetration test is fundamentally designed to evaluate whether an organization's security posture and implemented controls effectively meet the requirements of specific regulatory, industry, or internal security standards and policies.

Dobtaining specific information from the protected network.

Obtaining specific information from the protected network is a common objective for many penetration tests, but for a compliance-based test, this is done to verify that data protection controls mandated by compliance standards are effective, not as the standalone primary goal.

Concept tested: Types of penetration tests - Compliance

Source: https://www.pcisecuritystandards.org/documents/Penetration-Testing-Guidance-v2_1.pdf

Topics

#Compliance testing#Security standards#Penetration test objectives

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice