Study. uk . com
  1. Home
  2. All questions
  3. Question 374

CISSP study material · question 374 of 500

A board asks why a clean penetration test report does not mean the organisation is secure. Which two reasons does SP 800-115 give? Choose two.

  1. Testing cannot detect any weakness that has a published identifier.
  2. Attackers take whatever time they need and are not bound by constraints testers accept.
  3. Testing results expire the moment the report is issued.
  4. Testing has a narrow scope because of resource limits, particularly time.
Show the answer

Answer: D. Testing has a narrow scope because of resource limits, particularly time.
B. Attackers take whatever time they need and are not bound by constraints testers accept.

Testing is not comprehensive and is narrowed by resource limits, while an attacker takes whatever time is needed and accepts disruption a tester would avoid.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.3 Comparing Tests and Examinations

Challenge yourself on this topic → Study as cards