Certified Information Systems Security Professional CISSP · Free Practice Question Hard
Question 51
A security consultant has been tasked with identifying exploitable vulnerabilities within an internally developed application as part of a broader security evaluation. Which of the following methods would provide the MOST EFFECTIVE means of fulfilling this task?
- A Use a vulnerability assessment tool to uncover software flaws.
- B Perform a penetration test that includes manual and automated exploitation attempts.
- C Conduct a security control assessment to identify gaps in protection mechanisms.
- D Execute a misuse case test to simulate abnormal but potential system behavior.
Reveal correct answer
Correct answer: B
Explanation
OBJ. 6.2 - A penetration test is designed to not only identify vulnerabilities but also actively exploit them to determine the potential real-world impact. This method goes beyond vulnerability assessment, which only identifies weaknesses without exploitation. Misuse case testing focuses on nonstandard usage scenarios, and security control assessments do not directly involve the exploitation of vulnerabilities. For support or reporting issues, include Question ID: 67d968f956817fab03c8a8c8 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
