nerdexam
(ISC)2

SSCP · Question #1324

Penetration testing involves three steps. Identify the three steps below:<br>(Choose three)

The correct answer is B. Network reconnaissance C. Network Penetration D. System Control. Penetration testing typically involves phases such as reconnaissance to gather information, actual penetration to exploit vulnerabilities, and maintaining system control or access.

Submitted by renata2k· Apr 18, 2026Security Operations and Administration

Question

Penetration testing involves three steps. Identify the three steps below:<br>(Choose three)

Options

  • AWar Driving
  • BNetwork reconnaissance
  • CNetwork Penetration
  • DSystem Control
  • EDenial of system services
  • FNetwork scanning

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    87% (40)
  • E
    7% (3)
  • F
    4% (2)

Why each option

Penetration testing typically involves phases such as reconnaissance to gather information, actual penetration to exploit vulnerabilities, and maintaining system control or access.

AWar Driving

War Driving is a specific type of wireless reconnaissance, not a general phase of penetration testing.

BNetwork reconnaissanceCorrect

Network reconnaissance is the initial phase where information about the target system is gathered.

CNetwork PenetrationCorrect

Network penetration involves actively exploiting identified vulnerabilities to gain access to the target.

DSystem ControlCorrect

System control, or maintaining access, is the phase where the tester establishes persistence and escalates privileges to demonstrate potential impact.

EDenial of system services

Denial of system services is a potential outcome or impact of a successful attack, not a standard step in penetration testing methodology itself.

FNetwork scanning

Network scanning is a technique used within the reconnaissance phase, not a separate primary phase.

Concept tested: Penetration testing phases

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing

Topics

#Penetration testing phases#Reconnaissance#Exploitation#Post-exploitation

Community Discussion

No community discussion yet for this question.

Full SSCP Practice