Certified Ethical Hacker CEH · Free Practice Question Easy
Question 68
Which of the following is usually not considered when evaluating the attack surface of an organization?
- A External and internal users
- B Websites and cloud entities
- C Software applications
- D Software development lifecycle model
Reveal correct answer
Correct answer: D
Explanation
OBJ-2.1: The software development lifecycle model used by a company is purely an internal function relevant only to the development of custom software within the organization. Regardless of whether a waterfall or agile methodology is chosen, it does not directly affect the organization's attack surface. The attack surface represents the set of things that could be attacked by an adversary. External and internal users, websites, cloud entities, and software applications used by an organization are all possible entry points that an adversary could attempt an attack upon.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
