nerdexam
CompTIA

SY0-301 · Question #651

A security administrator is aware that a portion of the company's Internet-facing network tends to be non-secure due to poorly configured and patched systems. The business owner has accepted the…

The correct answer is C. Penetration test. The administrator wants to actively exploit the already-risky systems to measure how far an attacker could pivot into the internal network - this is the definition of a penetration test.

Threats, vulnerabilities, and mitigations

Question

A security administrator is aware that a portion of the company's Internet-facing network tends to be non-secure due to poorly configured and patched systems. The business owner has accepted the risk of those systems being compromised, but the administrator wants to determine the degree to which those systems can be used to gain access to the company intranet. Which of the following should the administrator perform?

Options

  • APatch management assessment
  • BBusiness impact assessment
  • CPenetration test
  • DVulnerability assessment

How the community answered

(37 responses)
  • A
    14% (5)
  • B
    5% (2)
  • C
    73% (27)
  • D
    8% (3)

Why each option

The administrator wants to actively exploit the already-risky systems to measure how far an attacker could pivot into the internal network - this is the definition of a penetration test.

APatch management assessment

A patch management assessment evaluates the patching posture of systems but does not simulate an attack or test lateral movement into the intranet.

BBusiness impact assessment

A business impact assessment quantifies the effect of a risk on business operations and is a planning document, not a technical test of network access.

CPenetration testCorrect

A penetration test goes beyond identifying vulnerabilities and actively attempts to exploit systems to determine the full extent of a compromise. In this scenario, the administrator wants to simulate an attacker using the poorly secured systems as a launching point to reach the intranet, which is exactly what a penetration test measures. The business owner has already accepted the risk, so the goal is scoping the blast radius, not remediation.

DVulnerability assessment

A vulnerability assessment identifies and classifies vulnerabilities but stops short of actively exploiting them to test whether intranet access is achievable.

Concept tested: Penetration testing vs vulnerability assessment scope

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#penetration testing#lateral movement#risk acceptance#network security

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice