Certified Information Security Manager CISM · Free Practice Question Medium

Question 32

What distinguishes double blind testing from blind testing in penetration testing?
  • A A) The tester is not provided with any information about the network
  • B B) Both the tester and the organization's security team are unaware of the test details
  • C C) The tester is provided with detailed information about the network
  • D D) The test is conducted without the knowledge of the organization's IT team
Reveal correct answer

Correct answer: B

Explanation

Explanation: In double blind testing, neither the tester nor the organization's security team knows the test details, simulating a real attack scenario. Explanation for Incorrect Options: A) Incorrect. This describes blind testing, where the tester is not provided with information about the network. C) Incorrect. Detailed information about the network is not provided in blind or double blind testing scenarios. D) Incorrect. This is not a distinguishing feature of double blind testing; it may apply to blind testing but not exclusively.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need