ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 259 - CS0-003 discussion

Report
Export

An organization is conducting a pilot deployment of an e-commerce application. The application's source code is not available. Which of the following strategies should an analyst recommend to evaluate the security of the software?

A.
Static testing
Answers
A.
Static testing
B.
Vulnerability testing
Answers
B.
Vulnerability testing
C.
Dynamic testing
Answers
C.
Dynamic testing
D.
Penetration testing
Answers
D.
Penetration testing
Suggested answer: D

Explanation:

Penetration testing is the best strategy to evaluate the security of the software without the source code. Penetration testing is a type of security testing that simulates real-world attacks on the software to identify and exploit its vulnerabilities. Penetration testing can be performed on the software as a black box, meaning that the tester does not need to have access to the source code or the internal structure of the software. Penetration testing can help the analyst to assess the security posture of the software, the potential impact of the vulnerabilities, and the effectiveness of the existing security controls12. Static testing, vulnerability testing, and dynamic testing are other types of security testing, but they usually require access to the source code or the internal structure of the software. Static testing is the analysis of the software code or design without executing it. Vulnerability testing is the identification and evaluation of the software weaknesses or flaws. Dynamic testing is the analysis of the software code or design while executing it345.

Reference: Penetration Testing - OWASP, What is a Penetration Test and How Does It Work?, Static Code Analysis | OWASP Foundation, Vulnerability Scanning Best Practices, Dynamic Testing - OWASP

asked 02/10/2024
Venkatesh Ampolu
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first