- Home
- All questions
- Question 374
CISSP study material · question 374 of 500
A board asks why a clean penetration test report does not mean the organisation is secure. Which two reasons does SP 800-115 give? Choose two.
Show the answer
Answer: D. Testing has a narrow scope because of resource limits, particularly time.
B. Attackers take whatever time they need and are not bound by constraints testers accept.
Testing is not comprehensive and is narrowed by resource limits, while an attacker takes whatever time is needed and accepts disruption a tester would avoid.
Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.3 Comparing Tests and Examinations