Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementEasy
A small business has recently installed a new web application and wants to ensure it is secure against common web vulnerabilities. They have limited budget and technical staff. Which type of vulnerability assessment would be most appropriate for their initial security review?
- ASource code review conducted by an in-house development team.
- BA full-scope, black-box penetration test.
- CAutomated vulnerability scanning using an industry-standard tool.
- DManual penetration testing by an external red team.
Show answer & explanationAnswer & explanation
Correct answer: C. Automated vulnerability scanning using an industry-standard tool.
Automated vulnerability scanning is cost-effective, requires less specialized staff than manual testing, and effectively identifies common vulnerabilities, making it ideal for a small business with budget and staff limitations for an initial review.
Why the other options are wrong
- A. Source code review requires highly specialized skills and is often more costly and time-consuming.
- B. A full-scope black-box penetration test is comprehensive but also the most expensive and resource-intensive option.
- D. Manual penetration testing is typically more expensive and resource-intensive.
Vulnerability Scanning
An automated process of identifying security weaknesses and misconfigurations in a network, system, or application using specialized software.
- Automated and scalable.
- Identifies known vulnerabilities.
- Less expensive than manual testing.
Memory trick: Start smart, scan for quick wins.