Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 Exam CISSP Topic 5 Question 97 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 97
Topic #: 5
[All CISSP Questions]

The overall goal of a penetration test is to determine a system's

Show Suggested Answer Hide Answer
Suggested Answer: B

The most important statement to convey to reviewers when setting expectations for reviewing the results of a security test is that the results of the tests represent a point-in-time assessment of the target(s). A security test is a process of evaluating and measuring the security posture and performance of an information system or a network, by using various tools, techniques, and methods, such as vulnerability scanning, penetration testing, or security auditing. The results of a security test reflect the security state of the target(s) at the time of the test, and they may not be valid or accurate for a different time period, as the security environment and conditions may change due to various factors, such as new threats, patches, updates, or configurations. Therefore, reviewers should understand that the results of a security test are not definitive or permanent, but rather indicative or temporary, and that they should be interpreted and used accordingly. The statement that the target's security posture cannot be further compromised is not true, as a security test does not guarantee or ensure the security of the target(s), but rather identifies and reports the security issues or weaknesses that may exist. The statement that the accuracy of testing results can be greatly improved if the target(s) are properly hardened is not relevant, as a security test is not meant to improve the accuracy of the results, but rather to assess the security of the target(s), and hardening the target(s) before the test may not reflect the actual or realistic security posture of the target(s). The statement that the deficiencies identified can be corrected immediately is not realistic, as a security test may identify various types of deficiencies that may require different levels of effort, time, and resources to correct, and some deficiencies may not be correctable at all, due to technical, operational, or financial constraints.


Contribute your Thoughts:

Noel
3 days ago
I'm not sure, but I think it could be D. We want to know how reliable the system is under stress, right?
upvoted 0 times
...
Kirby
6 days ago
I think the answer is A. The goal of a penetration test is to find vulnerabilities and assess the system's ability to withstand attacks.
upvoted 0 times
...
Fernanda
12 days ago
I believe it's important to also consider the system's reliability under stress, so I would go with option D.
upvoted 0 times
...
Ryann
14 days ago
I agree with Yong, it's all about testing the system's security under attack.
upvoted 0 times
...
Yong
16 days ago
I think the overall goal is to determine a system's ability to withstand an attack.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77