PT0-002 · Question #605
A customer hires a penetration tester to perform a penetration test on a web application. The customer wants the tester to test every major attack vector that could allow an attacker to exploit the…
The correct answer is B. OWASP. For a penetration test focusing on every major attack vector of a web application, the OWASP framework is the best methodology to use due to its specific web application security focus.
Question
A customer hires a penetration tester to perform a penetration test on a web application. The customer wants the tester to test every major attack vector that could allow an attacker to exploit the web application. Which of the following is the best methodology/framework for the tester to use?
Options
- APCI DSS
- BOWASP
- CMITRE ATT&CK
- DPTES
How the community answered
(52 responses)- A8% (4)
- B87% (45)
- C4% (2)
- D2% (1)
Why each option
For a penetration test focusing on every major attack vector of a web application, the OWASP framework is the best methodology to use due to its specific web application security focus.
PCI DSS (Payment Card Industry Data Security Standard) is a compliance standard for organizations handling payment card information, not a general penetration testing methodology for web applications.
The OWASP (Open Web Application Security Project) framework provides extensive resources, methodologies, and guidelines specifically tailored for web application security testing, including the OWASP Top 10 and the OWASP Testing Guide, which comprehensively cover major web application attack vectors.
MITRE ATT&CK is a knowledge base of adversary tactics and techniques for enterprise-level attacks and red teaming, which is broader than and not as specifically focused on web application vulnerabilities as OWASP.
PTES (Penetration Testing Execution Standard) is a general penetration testing methodology that covers various phases, but OWASP offers more specific and detailed guidance for web application attack vectors.
Concept tested: Web application penetration testing methodologies
Source: https://owasp.org/
Topics
Community Discussion
No community discussion yet for this question.