CompTIA PenTest+ (PT0-003)Engagement ManagementHard

A penetration tester following the OSSTMM methodology wants to quantify the target's actual security posture by comparing existing operational controls (limitations, porosity) against an idealized secure state, producing a normalized numeric score. Which OSSTMM concept does this describe?

  1. APTES threat modeling
  2. BOWASP Risk Rating Methodology
  3. CAttack surface mapping
  4. DRisk Assessment Value (RAV)
Show answer & explanation

Correct answer: D. Risk Assessment Value (RAV)

OSSTMM's Risk Assessment Value (RAV) is a scientific metric that quantifies the actual security level of a target by comparing operational controls against the ideal state, producing a standardized numeric score used for comparison over time.

Why the other options are wrong

  • A. PTES threat modeling maps threat actors to assets; it isn't an OSSTMM metric.
  • B. OWASP Risk Rating is a separate methodology used for web app vulnerability scoring, not OSSTMM.
  • C. Attack surface mapping identifies exposed entry points but doesn't produce OSSTMM's normalized score.

OSSTMM Risk Assessment Value (RAV)

A quantitative metric in OSSTMM that measures actual operational security by comparing existing controls to an ideal security state.

  • Produces a normalized, comparable score
  • Based on factors like porosity, limitations, controls
  • Allows tracking of security improvement over time

Memory trick: RAV = 'Real Actual Value' of your security

More Engagement Management questions