SY0-501 · Question #73
A security administrator is tasked with conducting an assessment made to establish the baseline security posture of the corporate IT infrastructure. The assessment must report actual flaws and…
The correct answer is D. Vulnerability assessment. The administrator is tasked with identifying actual flaws and weaknesses in the IT infrastructure without causing damage, which aligns with the objectives of a vulnerability assessment.
Question
A security administrator is tasked with conducting an assessment made to establish the baseline security posture of the corporate IT infrastructure. The assessment must report actual flaws and weaknesses in the infrastructure. Due to the expense of hiring outside consultants, the testing must be performed using in-house or cheaply available resource. There cannot be a possibility of any requirement being damaged in the test. Which of the following has the administrator been tasked to perform?
Options
- ARisk transference
- BPenetration test
- CThreat assessment
- DVulnerability assessment
How the community answered
(39 responses)- A8% (3)
- B15% (6)
- C5% (2)
- D72% (28)
Why each option
The administrator is tasked with identifying actual flaws and weaknesses in the IT infrastructure without causing damage, which aligns with the objectives of a vulnerability assessment.
Risk transference is a risk management strategy involving shifting the financial or operational burden of a potential risk to another party, rather than a method for assessing system flaws.
A penetration test involves actively attempting to exploit vulnerabilities to simulate a real attack, which inherently carries a risk of disrupting or damaging systems, contradicting the requirement that no equipment can be harmed.
A threat assessment primarily focuses on identifying potential threats and their characteristics, and how they might impact an organization, rather than specifically discovering existing technical flaws and weaknesses within the infrastructure itself.
A vulnerability assessment systematically identifies, quantifies, and ranks security weaknesses in a system or network through non-intrusive methods. This process allows for the discovery and reporting of actual flaws and weaknesses without exploiting them, thus ensuring no possibility of equipment damage while using internal resources to establish a security baseline.
Concept tested: Distinguishing security assessment types, specifically vulnerability assessments
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2-type-2-pen-test-and-va#differences-between-vulnerability-assessments-and-penetration-tests
Topics
Community Discussion
No community discussion yet for this question.