ExamGecko
Question list
Search
Search

Question 380 - CISM discussion

Report
Export

A penetration test against an organization's external web application shows several vulnerabilities. Which of the following presents the GREATEST concern?

A.
A rules of engagement form was not signed prior to the penetration test
Answers
A.
A rules of engagement form was not signed prior to the penetration test
B.
Vulnerabilities were not found by internal tests
Answers
B.
Vulnerabilities were not found by internal tests
C.
Vulnerabilities were caused by insufficient user acceptance testing (UAT)
Answers
C.
Vulnerabilities were caused by insufficient user acceptance testing (UAT)
D.
Exploit code for one of the vulnerabilities is publicly available
Answers
D.
Exploit code for one of the vulnerabilities is publicly available
Suggested answer: D

Explanation:

Exploit code for one of the vulnerabilities is publicly available presents the greatest concern because it means that anyone can easily exploit the vulnerability and compromise the web application. This increases the risk of data breach, denial of service, or other malicious attacks. Therefore, exploit code for one of the vulnerabilities is publicly available is the correct answer.

https://www.imperva.com/learn/application-security/penetration-testing/

https://www.netspi.com/blog/technical/web-application-penetration-testing/are-you-testing-your-web-application-for-vulnerabilities/

asked 01/10/2024
john ignacio echavarria lopez
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first