CompTIA PenTest+ (PT0-003)Engagement ManagementHard
A penetration tester following the OSSTMM methodology wants to quantify the target's actual security posture by comparing existing operational controls (limitations, porosity) against an idealized secure state, producing a normalized numeric score. Which OSSTMM concept does this describe?
- APTES threat modeling
- BOWASP Risk Rating Methodology
- CAttack surface mapping
- DRisk Assessment Value (RAV)
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Assessment Value (RAV)
OSSTMM's Risk Assessment Value (RAV) is a scientific metric that quantifies the actual security level of a target by comparing operational controls against the ideal state, producing a standardized numeric score used for comparison over time.
Why the other options are wrong
- A. PTES threat modeling maps threat actors to assets; it isn't an OSSTMM metric.
- B. OWASP Risk Rating is a separate methodology used for web app vulnerability scoring, not OSSTMM.
- C. Attack surface mapping identifies exposed entry points but doesn't produce OSSTMM's normalized score.
OSSTMM Risk Assessment Value (RAV)
A quantitative metric in OSSTMM that measures actual operational security by comparing existing controls to an ideal security state.
- Produces a normalized, comparable score
- Based on factors like porosity, limitations, controls
- Allows tracking of security improvement over time
Memory trick: RAV = 'Real Actual Value' of your security