ISC Certified Information Systems Security Professional (CISSP) CISSP Question # 165 Topic 17 Discussion
CISSP Exam Topic 17 Question 165 Discussion:
Question #: 165
Topic #: 17
An establish information technology (IT) consulting firm is considering acquiring a successful local startup. To gain a comprehensive understanding of the startup’s security posture’ which type of assessment provides the BEST information?
A penetration test is the best type of assessment to gain a comprehensive understanding of the startup’s security posture. A penetration test is a simulated attack on a system or a network, performed by authorized testers, to evaluate the security and vulnerability of the system or network. A penetration test can provide the following benefits for the IT consulting firm that is considering acquiring the startup:
It can reveal the actual risks and impacts of the potential attacks or threats on the system or network, by exploiting the vulnerabilities or weaknesses in the system or network.
It can measure the effectiveness and maturity of the security controls and policies implemented by the system or network, by testing the detection, prevention, and response capabilities of the system or network.
It can provide the recommendations and solutions for improving the security and resilience of the system or network, by identifying and prioritizing the remediation actions for the system or network. A penetration test can provide more comprehensive and realistic information about the startup’s security posture than other types of assessments, such as a security audit, a tabletop exercise, or a security threat model, which are more theoretical, formal, or hypothetical in nature. References: CISSP All-in-One Exam Guide, Chapter 6: Security Assessment and Testing, Section: Penetration Testing, pp. 553-554.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit