nerdexam
CompTIA

SY0-501 · Question #447

A Chief Information Officer (CIO) recently saw on the news that a significant security flaws exists with a specific version of a technology the company uses to support many critical application. The…

The correct answer is A. Penetration test. The CIO needs to assess the presence of a reported vulnerability and understand its potential impact or extent of harm to the organization.

Submitted by valeria.br· Mar 4, 2026Security operations

Question

A Chief Information Officer (CIO) recently saw on the news that a significant security flaws exists with a specific version of a technology the company uses to support many critical application. The CIO wants to know if this reported vulnerability exists in the organization and, if so, to what extent the company could be harmed. Which of the following would BEST provide the needed information?

Options

  • APenetration test
  • BVulnerability scan
  • CActive reconnaissance
  • DPatching assessment report

How the community answered

(52 responses)
  • A
    77% (40)
  • B
    2% (1)
  • C
    8% (4)
  • D
    13% (7)

Why each option

The CIO needs to assess the presence of a reported vulnerability and understand its potential impact or extent of harm to the organization.

APenetration testCorrect

A penetration test actively attempts to exploit identified vulnerabilities to demonstrate the actual risk and the potential impact an attacker could achieve. This method directly addresses the CIO's concern about the existence of the vulnerability and 'to what extent the company could be harmed' by a successful exploit.

BVulnerability scan

A vulnerability scan identifies known weaknesses and potential vulnerabilities but does not typically exploit them to determine the actual impact or extent of harm.

CActive reconnaissance

Active reconnaissance is a preliminary phase of information gathering about a target system or network, not an assessment of exploitability or potential harm.

DPatching assessment report

A patching assessment report checks the compliance and status of applied security patches, not the active exploitability or potential damage from a specific reported vulnerability.

Concept tested: Differentiating vulnerability assessment from penetration testing

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf

Topics

#penetration testing#vulnerability assessment#risk assessment#security testing

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice