Study. uk . com
  1. Home
  2. All questions
  3. Question 381

CISSP study material · question 381 of 500

Which four phases does SP 800-115 use for penetration testing, and what is unusual about the ordering?

  1. Planning, execution, analysis and closure, matching the general assessment phases.
  2. Reconnaissance, exploitation, escalation and cleanup, performed strictly in sequence.
  3. Scoping, scanning, exploitation and remediation, with remediation performed by the tester.
  4. Planning, discovery, attack and reporting, with the attack phase looping back into discovery.
Show the answer

Answer: D. Planning, discovery, attack and reporting, with the attack phase looping back into discovery.

SP 800-115 presents a four-stage methodology of planning, discovery, attack and reporting, with the attack phase looping back to discovery as further access reveals new targets.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 5.2.1 Penetration Testing Phases

Challenge yourself on this topic → Study as cards