ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 390 - PT0-002 discussion

Report
Export

After performing a web penetration test, a security consultant is ranking the findings by criticality. Which of the following standards or methodologies would be best for the consultant to use for reference?

A.
OWASP
Answers
A.
OWASP
B.
MITRE ATT&CK
Answers
B.
MITRE ATT&CK
C.
PTES
Answers
C.
PTES
D.
NIST
Answers
D.
NIST
Suggested answer: A

Explanation:

After performing a web penetration test, using the OWASP (Open Web Application Security Project) standards or methodologies would be the best choice for ranking the findings by criticality. OWASP is renowned for its comprehensive documentation and guidelines on web application security, including the well-known OWASP Top 10 list, which outlines the ten most critical web application security risks. This makes it an ideal reference for categorizing and prioritizing vulnerabilities discovered during a web penetration test.

While MITRE ATT&CK, PTES (Penetration Testing Execution Standard), and NIST (National Institute of Standards and Technology) provide valuable frameworks and methodologies for cybersecurity, OWASP's focus on web applications specifically makes it the most suitable for this context.

asked 02/10/2024
Jaime Ramirez
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first