SSCP · Question #1325
Penetration testing involves three steps. At which step should an approve penetration test stop?
The correct answer is C. Network Penetration. An approved penetration test typically stops after successfully demonstrating network penetration and the exploitation of vulnerabilities, before causing actual damage or prolonged disruption.
Question
Penetration testing involves three steps. At which step should an approve penetration test stop?
Options
- AWar Driving
- BNetwork reconnaissance
- CNetwork Penetration
- DSystem Control
- EDenial of system services
- FNetwork scanning
How the community answered
(16 responses)- C69% (11)
- D6% (1)
- E6% (1)
- F19% (3)
Why each option
An approved penetration test typically stops after successfully demonstrating network penetration and the exploitation of vulnerabilities, before causing actual damage or prolonged disruption.
War Driving is a reconnaissance technique, and stopping there would not demonstrate successful penetration.
Network reconnaissance is the information gathering phase; stopping here would not demonstrate system vulnerabilities or penetration.
An approved penetration test typically aims to demonstrate the successful exploitation of vulnerabilities and gain network penetration, stopping before causing actual harm or extended disruption to the target system.
System control implies maintaining persistent access and potentially escalating privileges, which might exceed the scope of what is permitted in a typical approved penetration test's stopping point without explicit authorization.
Denial of system services would be a destructive action and is generally not an intended stopping point for an approved penetration test, which seeks to identify vulnerabilities without causing harm.
Network scanning is a part of reconnaissance, and stopping there would not demonstrate successful penetration.
Concept tested: Penetration testing scope and limits
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing
Topics
Community Discussion
No community discussion yet for this question.