CompTIA Security+ (SY0-701)Security Program Management and OversightHard
A company's security team runs an automated scanner that identifies and lists known vulnerabilities on internal servers, including missing patches and outdated software versions, but does not attempt to exploit any of the findings. Which activity best describes this process?
- ABug bounty program
- BPenetration test
- CTabletop exercise
- DVulnerability assessment
Show answer & explanationAnswer & explanation
Correct answer: D. Vulnerability assessment
A vulnerability assessment identifies, catalogs, and prioritizes known weaknesses without actively exploiting them. A penetration test goes further by attempting to exploit vulnerabilities to demonstrate actual impact and access.
Why the other options are wrong
- A. A bug bounty program pays external researchers to find and report vulnerabilities, not an internal automated scan.
- B. A penetration test actively attempts exploitation, unlike this scan-only process.
- C. A tabletop exercise is a discussion-based simulation, unrelated to technical scanning.
Vulnerability Assessment vs. Penetration Test
A vulnerability assessment identifies and catalogs known weaknesses without exploitation, while a penetration test actively exploits vulnerabilities to demonstrate real-world impact.
- Vulnerability assessments are typically automated and broader in scope
- Penetration tests are more targeted and require exploitation authorization
- Both support the overall risk management process
Memory trick: Assess finds the door is unlocked; a pen test walks through it.