Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementEasy
A new regulation mandates that all sensitive data processing systems undergo a comprehensive security assessment annually. The assessment must include a method to simulate real-world attacks to identify exploitable vulnerabilities, not just potential ones. Which type of assessment would BEST fulfill this regulatory requirement?
- AVulnerability Scan
- BPenetration Test
- CSecurity Audit
- DRisk Assessment
Show answer & explanationAnswer & explanation
Correct answer: B. Penetration Test
A penetration test is designed to simulate real-world attacks and actively exploit vulnerabilities to determine their real-world impact and confirm exploitability, which directly aligns with the requirement to identify exploitable vulnerabilities through simulated attacks.
Why the other options are wrong
- A. A vulnerability scan identifies potential weaknesses but typically does not attempt to exploit them.
- C. A security audit checks compliance against standards but does not necessarily simulate attacks.
- D. A risk assessment identifies and evaluates risks but does not perform technical attacks.
Penetration Testing
A simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities.
- Actively exploits vulnerabilities.
- Provides a real-world perspective of an attacker.
- Requires explicit authorization (Rules of Engagement).
Memory trick: Penetration testing is like a 'practice attack' to find true weaknesses.