Study. uk . com
  1. Home
  2. All questions
  3. Question 383

CISSP study material · question 383 of 500

Which two halves make up the discovery phase of a penetration test in SP 800-115? Choose two.

  1. Vulnerability analysis, comparing what was found against vulnerability databases and the tester's own knowledge.
  2. Information gathering and scanning, including port and service identification.
  3. Exploitation of the weaknesses found, to verify they are real.
  4. Reporting of the findings to management.
Show the answer

Answer: A. Vulnerability analysis, comparing what was found against vulnerability databases and the tester's own knowledge.
B. Information gathering and scanning, including port and service identification.

The discovery phase has two parts: information gathering and scanning, then vulnerability analysis comparing scanned services, applications and operating systems against databases and the tester's knowledge.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 5.2.1 Penetration Testing Phases

Challenge yourself on this topic → Study as cards