nerdexam
CompTIA

PT0-002 · Question #191

A company has recruited a penetration tester to conduct a vulnerability scan over the network. The test is confirmed to be on a known environment. Which of the following would be the BEST option to…

The correct answer is A. Asset inventory. For a known environment, consulting the existing asset inventory is the most accurate and efficient method to properly identify all systems and their configurations prior to conducting any penetration test or vulnerability scan.

Planning and Scoping

Question

A company has recruited a penetration tester to conduct a vulnerability scan over the network. The test is confirmed to be on a known environment. Which of the following would be the BEST option to identify a system properly prior to performing the assessment?

Options

  • AAsset inventory
  • BDNS records
  • CWeb-application scan
  • DFull scan

How the community answered

(45 responses)
  • A
    91% (41)
  • B
    4% (2)
  • C
    2% (1)
  • D
    2% (1)

Why each option

For a known environment, consulting the existing asset inventory is the most accurate and efficient method to properly identify all systems and their configurations prior to conducting any penetration test or vulnerability scan.

AAsset inventoryCorrect

An asset inventory provides a pre-existing, documented, and verified list of all systems, hardware, software, and network components within the known environment, serving as the most accurate foundation for scope definition and proper system identification before an assessment.

BDNS records

DNS records primarily map hostnames to IP addresses and may not provide a complete list of all internal systems or detailed system configurations for a comprehensive assessment.

CWeb-application scan

A web-application scan focuses specifically on web applications and would not provide a complete identification of all systems, services, and devices across the entire network.

DFull scan

A full scan (e.g., network or vulnerability scan) is an active discovery and assessment technique performed during the engagement, rather than a method for prior proper identification of systems in a known environment.

Concept tested: Penetration testing reconnaissance, scope definition

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v2-asset-management

Topics

#Asset management#Pre-assessment#Scoping#Information gathering

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice