ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 469 - CAS-004 discussion

Report
Export

A company recently migrated its critical web application to a cloud provider's environment. As part of the company's risk management program, the company intends to conduct an external penetration test. According to the scope of work and the rules of engagement, the penetration tester will validate the web application's security and check for opportunities to expose sensitive company information in the newly migrated cloud environment. Which of the following should be the first consideration prior to engaging in the test?

A.
Prepare a redundant server to ensure the critical web application's availability during the test.
Answers
A.
Prepare a redundant server to ensure the critical web application's availability during the test.
B.
Obtain agreement between the company and the cloud provider to conduct penetration testing.
Answers
B.
Obtain agreement between the company and the cloud provider to conduct penetration testing.
C.
Ensure the latest patches and signatures are deployed on the web server.
Answers
C.
Ensure the latest patches and signatures are deployed on the web server.
D.
Create an NDA between the external penetration tester and the company.
Answers
D.
Create an NDA between the external penetration tester and the company.
Suggested answer: B

Explanation:

Before conducting a penetration test in a cloud environment, it is critical to first obtain permission from the cloud service provider. Cloud providers often have strict rules about penetration testing to avoid unintended service disruptions or violations of service agreements. Without this agreement, the company could face legal or operational consequences. This aligns with CASP+ best practices, which emphasize the importance of securing approval and understanding shared responsibility models in cloud environments before engaging in security testing.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (Penetration Testing in Cloud Environments)

CompTIA CASP+ Study Guide: Cloud Security and Legal Considerations for Penetration Testing

asked 02/10/2024
Luis Alfonso Rodriguez Castro
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first