nerdexam
CompTIA

PT0-002 · Question #50

A company that developers embedded software for the automobile industry has hired a penetration-testing team to evaluate the security of its products prior to delivery. The penetration- testing team…

The correct answer is A. The reverse-engineering team may have a history of selling exploits to third parties. The penetration testers have the intention of creating exploits, so obviously exploits are going to be the concern in this scenario no doubt about that.

Engagement management

Question

A company that developers embedded software for the automobile industry has hired a penetration-testing team to evaluate the security of its products prior to delivery. The penetration- testing team has stated its intent to subcontract to a reverse-engineering team capable of analyzing binaries to develop proof-of-concept exploits. The software company has requested additional background investigations on the reverse-engineering team prior to approval of the subcontract. Which of the following concerns would BEST support the software company's request?

Options

  • AThe reverse-engineering team may have a history of selling exploits to third parties.
  • BThe reverse-engineering team may use closed-source or other non-public information feeds for its
  • CThe reverse-engineering team may not instill safety protocols sufficient for the automobile
  • DThe reverse-engineering team will be given access to source code for analysis.

How the community answered

(39 responses)
  • A
    64% (25)
  • B
    5% (2)
  • C
    10% (4)
  • D
    21% (8)

Explanation

The penetration testers have the intention of creating exploits, so obviously exploits are going to be the concern in this scenario no doubt about that.

Topics

#Third-party risk management#Vendor assessment#Subcontracting security services#Ethical considerations

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice