CompTIA PenTest+: Scoping an Engagement

Réussis tes devoirs et examens dès maintenant avec Quizwiz!

Which of the following would be considered examples of hostile threat actors?

Corporate competitor Disgruntled ex-employee Hacktivist Cyber miner

Which one of the following would NOT be a reason to perform compliance testing?

ISACA

In order to have clearly defined penetration objectives based on regulations, methodologies are commonly based on the industry-accepted penetration testing approaches. Which one of the following would NOT apply?

MARS-E

What is one of the quickest ways for a penetration testing firm to lose customers and potentially go out of business?

Regularly allowing for scope creep

What type of risk treatment often involves cyber insurance?

Risk transfer

What type of test is best characterized by both the tester and security teams working together and appraising each other of their movements?

Targeted test

Which of the following statements is NOT true concerning the pre-engagement scoping meeting?

This stage is much too soon for signing NDAs

A penetration tester has wide-ranging knowledge and visibility into the target system or application. Which type of test is this?

White box


Ensembles d'études connexes

Speak Up! Chapter 10 (Key Terms and Review Questions)

View Set

Chapter 18 Positive Punishment Procedures and the Ethics of Punishment

View Set

Unit 4 Estate Planning FINA 4397

View Set