Study. uk . com
  1. Home
  2. All questions
  3. Question 55

CISSP study material · question 55 of 500

A bank's board wants to learn how far an intruder could get before the security operations centre reacts, so the exercise must run while operations staff remain unaware of it. The assessors ask what has to be in place before they begin. Which condition governs this kind of exercise?

  1. The system owner authorises the exercise and the target list is shared with the incident response team beforehand
  2. Senior management authorises the exercise, and a trusted intermediary can confirm to responders that an attack is the test
  3. The assessors authorise their own scope, because covert value is lost once anyone inside the organisation is informed
  4. The security operations centre manager authorises the exercise and briefs analysts on the window when attacks will occur
Show the answer

Answer: B. Senior management authorises the exercise, and a trusted intermediary can confirm to responders that an attack is the test

Covert testing hides from IT staff but proceeds only with senior management permission, using a trusted intermediary who verifies that an attack is the test before responders escalate.

Source: NIST SP 800-115 (NIST) — SP 800-115 > Section 2.4.2, Overt and Covert

Challenge yourself on this topic → Study as cards