Study. uk . com
  1. Home
  2. All questions
  3. Question 380

CISSP study material · question 380 of 500

A sponsor expects a covert test to deliver a complete inventory of the organisation's vulnerabilities. Which two corrections does SP 800-115 support? Choose two.

  1. Covert testing examines the damage or impact an adversary can cause rather than identifying vulnerabilities.
  2. Covert testing is limited to externally facing systems by definition.
  3. Covert testing must be preceded by a full vulnerability scan to be valid.
  4. Covert testing does not exercise every control, find every vulnerability, or cover every system.
Show the answer

Answer: A. Covert testing examines the damage or impact an adversary can cause rather than identifying vulnerabilities.
D. Covert testing does not exercise every control, find every vulnerability, or cover every system.

Covert testing measures the damage an adversary could cause; it does not exercise every control, find every vulnerability, or reach every system in the organisation.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.4.2 Overt and Covert

Challenge yourself on this topic → Study as cards