Study. uk . com
  1. Home
  2. All questions
  3. Question 376

CISSP study material · question 376 of 500

An organisation wants to understand what damage a contractor with network access could cause. Which testing viewpoint does SP 800-115 describe for this?

  1. External testing, which works from outside the security perimeter.
  2. Internal testing, which assumes the identity of a trusted insider or an attacker past the perimeter.
  3. Covert testing, which hides the exercise from technology staff.
  4. Overt testing, which proceeds with the knowledge of technology staff.
Show the answer

Answer: B. Internal testing, which assumes the identity of a trusted insider or an attacker past the perimeter.

For internal security testing, assessors work from the internal network assuming the identity of a trusted insider or of an attacker who has penetrated perimeter defences.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.4.1 External and Internal

Challenge yourself on this topic → Study as cards