ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 46 - ECSS discussion

Report
Export

John, a professional penetration tester, was hired by an organization for conducting a penetration test on their IT infrastructure. He was assigned the task of identifying risks, rather than finding vulnerabilities. In this process, he defined the goal before initiating the penetration test and performed multiple parallel processes to achieve the goal.

Identify the type of penetration assessment performed by John in the above scenario.

A.

Red team oriented penetration testing approach

Answers
A.

Red team oriented penetration testing approach

B.

Objective-oriented penetration testing approach

Answers
B.

Objective-oriented penetration testing approach

C.

Adversarial goal based assessment

Answers
C.

Adversarial goal based assessment

D.

Compliance oriented penetration testing approach

Answers
D.

Compliance oriented penetration testing approach

Suggested answer: B

Explanation:

In the scenario described, John's approach aligns withobjective-oriented penetration testing. In this method, the tester defines specific goals or objectives before initiating the penetration test. The focus is on identifying risks related to achieving those objectives rather than merely finding vulnerabilities. By performing multiple parallel processes to achieve the defined goal, John is following an objective-oriented approach.

https://www.synopsys.com/glossary/what-is-red-teaming.html

asked 24/10/2024
Yohan Frachisse
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first