Study. uk . com
  1. Home
  2. All questions
  3. Question 370

CISSP study material · question 370 of 500

An organisation buys an annual penetration test and performs no other technical assessment. Which two points from SP 800-115 argue against relying on one technique? Choose two.

  1. A penetration test is prohibited unless preceded by a documentation review.
  2. A penetration test cannot be performed from an external viewpoint.
  3. No single technique can provide a complete picture of a system's or network's security.
  4. A penetration test itself normally depends on port and service identification and vulnerability scanning to find targets.
Show the answer

Answer: C. No single technique can provide a complete picture of a system's or network's security.
D. A penetration test itself normally depends on port and service identification and vulnerability scanning to find targets.

SP 800-115 says organisations should combine techniques since none gives a complete picture, and notes penetration testing usually relies on port and service identification and vulnerability scanning.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.2 Technical Assessment Techniques

Challenge yourself on this topic → Study as cards