ISC2 Certified in Cybersecurity (CC)Security OperationsEasy
An organization is deploying a new web application that will process sensitive customer payment information. Before going live, the security team wants to identify and remediate any potential weaknesses in the application's code and infrastructure that could be exploited by an attacker. They decide to use automated tools to methodically check the system against known vulnerabilities. Which security operation are they performing?
- APenetration Testing
- BSecurity Monitoring
- CVulnerability Scanning
- DSecurity Audits
Show answer & explanationAnswer & explanation
Correct answer: C. Vulnerability Scanning
Vulnerability scanning uses automated tools to identify known weaknesses in systems, applications, and networks by comparing them against a database of known vulnerabilities. This aligns with the scenario's goal of identifying potential weaknesses using automated tools before deployment.
Why the other options are wrong
- A. Penetration testing simulates an actual attack, which is more involved than just identifying known weaknesses.
- B. Security monitoring is continuous observation, not a pre-deployment weakness identification.
- D. Security audits review compliance, not primarily technical weaknesses with automated tools.
Vulnerability Scanning
The automated process of identifying known security weaknesses or flaws in a system, network, or application.
- Uses automated tools and vulnerability databases.
- Identifies potential attack vectors.
- Helps prioritize remediation efforts.
Memory trick: Scans Spot System Shortcomings.