- Home
- All questions
- Question 370
CISSP study material · question 370 of 500
An organisation buys an annual penetration test and performs no other technical assessment. Which two points from SP 800-115 argue against relying on one technique? Choose two.
Show the answer
Answer: C. No single technique can provide a complete picture of a system's or network's security.
D. A penetration test itself normally depends on port and service identification and vulnerability scanning to find targets.
SP 800-115 says organisations should combine techniques since none gives a complete picture, and notes penetration testing usually relies on port and service identification and vulnerability scanning.
Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.2 Technical Assessment Techniques