Certified In Cybersecurity CC · Free Practice Question Easy

Question 12

Which of the following is a type of security testing that involves deliberately trying to breach the security of a system to identify vulnerabilities?
  • A Break attack simulations (BAS)
  • B Penetration testing
  • C Vulnerability scanning
  • D Security auditing
Reveal correct answer

Correct answer: B

Explanation

The correct answer: Penetration testing involves simulating an attack on a system to identify vulnerabilities that could be exploited by a real attacker. Penetration testers, or "ethical hackers," use the same techniques as malicious hackers, but they do it legally and ethically, to identify and document vulnerabilities that could be exploited. The goal of penetration testing is to identify weak points in an organization's security posture before they can be exploited by a real attacker. The incorrect answers: Vulnerability scanning is another type of security testing that that involves using automated tools to identify potential vulnerabilities in a system. It doesn't involve the active attempt to breach a system's defenses that characterizes penetration testing. Security auditing involves evaluating the security policies, procedures, and controls in place on a system. A security audit might include penetration testing but it also includes things like policy review and compliance checks. It is not focused solely on trying to breach a system's defenses. Break attack simulations (BAS) share some similarities with penetration testing but instead of a manual, targeted approach used in penetration testing, it's more focused on using continuous automated attacks.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need