EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium

A security team is reviewing their vulnerability management program. They are debating whether to primarily rely on automated vulnerability scanning or manual penetration testing. Which of the following is a key advantage of manual penetration testing over automated vulnerability scanning?

  1. AIt is generally less expensive to perform regularly.
  2. BIt provides a comprehensive report with CVSS scores for identified vulnerabilities.
  3. CIt can scan a larger number of systems in a shorter amount of time.
  4. DIt can identify business logic flaws and complex chained vulnerabilities.
Show answer & explanation

Correct answer: D. It can identify business logic flaws and complex chained vulnerabilities.

Manual penetration testing involves human intelligence and creativity, allowing testers to understand the business context, chain multiple seemingly minor vulnerabilities, and identify complex logic flaws that automated scanners often miss. Scanners are good for breadth but lack the depth and contextual understanding of a human.

Why the other options are wrong

  • A. Automated scanning is typically less expensive for routine checks.
  • B. Both can provide reports with CVSS scores, but automated scanners often generate these more readily.
  • C. Automated scanners excel at scanning many systems quickly.

Manual Penetration Testing

A proactive and authorized attempt to find security weaknesses in a system by simulating real-world attacks using human expertise, creativity, and knowledge of attacker methodologies.

  • Identifies complex, chained, and logical vulnerabilities.
  • Requires skilled human testers.
  • Provides deeper insights into potential attack paths than automated tools.

Memory trick: For 'deep' insights, you need 'human' intelligence, not just 'robot' scanning.

More System Hacking Phases and Attack Techniques questions