nerdexam
CompTIA

PT0-002 · Question #605

A customer hires a penetration tester to perform a penetration test on a web application. The customer wants the tester to test every major attack vector that could allow an attacker to exploit the…

The correct answer is B. OWASP. For a penetration test focusing on every major attack vector of a web application, the OWASP framework is the best methodology to use due to its specific web application security focus.

Planning and Scoping

Question

A customer hires a penetration tester to perform a penetration test on a web application. The customer wants the tester to test every major attack vector that could allow an attacker to exploit the web application. Which of the following is the best methodology/framework for the tester to use?

Options

  • APCI DSS
  • BOWASP
  • CMITRE ATT&CK
  • DPTES

How the community answered

(52 responses)
  • A
    8% (4)
  • B
    87% (45)
  • C
    4% (2)
  • D
    2% (1)

Why each option

For a penetration test focusing on every major attack vector of a web application, the OWASP framework is the best methodology to use due to its specific web application security focus.

APCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is a compliance standard for organizations handling payment card information, not a general penetration testing methodology for web applications.

BOWASPCorrect

The OWASP (Open Web Application Security Project) framework provides extensive resources, methodologies, and guidelines specifically tailored for web application security testing, including the OWASP Top 10 and the OWASP Testing Guide, which comprehensively cover major web application attack vectors.

CMITRE ATT&CK

MITRE ATT&CK is a knowledge base of adversary tactics and techniques for enterprise-level attacks and red teaming, which is broader than and not as specifically focused on web application vulnerabilities as OWASP.

DPTES

PTES (Penetration Testing Execution Standard) is a general penetration testing methodology that covers various phases, but OWASP offers more specific and detailed guidance for web application attack vectors.

Concept tested: Web application penetration testing methodologies

Source: https://owasp.org/

Topics

#Web application penetration testing#Penetration testing methodology#OWASP#Frameworks

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice