PT0-002 · Question #355
After performing a web penetration test, a security consultant is ranking the findings by criticality. Which of the following standards or methodologies would be best for the consultant to use for…
The correct answer is A. OWASP. For ranking web penetration test findings by criticality, the OWASP Top 10 is the best reference standard.
Question
After performing a web penetration test, a security consultant is ranking the findings by criticality. Which of the following standards or methodologies would be best for the consultant to use for reference?
Options
- AOWASP
- BMITRE ATT&CK
- CPTES
- DNIST
How the community answered
(62 responses)- A95% (59)
- B2% (1)
- D3% (2)
Why each option
For ranking web penetration test findings by criticality, the OWASP Top 10 is the best reference standard.
The OWASP (Open Web Application Security Project) Top 10 provides a regularly updated list of the most critical web application security risks, along with detailed explanations and remediation guidance. It is specifically designed for web applications and is widely recognized as the authoritative standard for understanding and ranking web application vulnerabilities by criticality.
MITRE ATT&CK is a knowledge base of adversary tactics and techniques across various platforms, focusing on attacker behavior rather than specific web application vulnerabilities and their criticality ranking.
PTES (Penetration Testing Execution Standard) is a comprehensive standard for penetration testing, outlining its phases, but it does not primarily focus on ranking web application findings by criticality.
NIST (National Institute of Standards and Technology) provides various cybersecurity frameworks and guidelines, but none are as specifically tailored for ranking web application vulnerabilities by criticality as the OWASP Top 10.
Concept tested: Web application vulnerability classification
Source: https://owasp.org/www-project-top-ten/
Topics
Community Discussion
No community discussion yet for this question.