SY0-501 · Question #447
A Chief Information Officer (CIO) recently saw on the news that a significant security flaws exists with a specific version of a technology the company uses to support many critical application. The…
The correct answer is A. Penetration test. The CIO needs to assess the presence of a reported vulnerability and understand its potential impact or extent of harm to the organization.
Question
A Chief Information Officer (CIO) recently saw on the news that a significant security flaws exists with a specific version of a technology the company uses to support many critical application. The CIO wants to know if this reported vulnerability exists in the organization and, if so, to what extent the company could be harmed. Which of the following would BEST provide the needed information?
Options
- APenetration test
- BVulnerability scan
- CActive reconnaissance
- DPatching assessment report
How the community answered
(52 responses)- A77% (40)
- B2% (1)
- C8% (4)
- D13% (7)
Why each option
The CIO needs to assess the presence of a reported vulnerability and understand its potential impact or extent of harm to the organization.
A penetration test actively attempts to exploit identified vulnerabilities to demonstrate the actual risk and the potential impact an attacker could achieve. This method directly addresses the CIO's concern about the existence of the vulnerability and 'to what extent the company could be harmed' by a successful exploit.
A vulnerability scan identifies known weaknesses and potential vulnerabilities but does not typically exploit them to determine the actual impact or extent of harm.
Active reconnaissance is a preliminary phase of information gathering about a target system or network, not an assessment of exploitability or potential harm.
A patching assessment report checks the compliance and status of applied security patches, not the active exploitability or potential damage from a specific reported vulnerability.
Concept tested: Differentiating vulnerability assessment from penetration testing
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Topics
Community Discussion
No community discussion yet for this question.