exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 3 discussion

Actual exam question from CompTIA's PT0-002
Question #: 3
Topic #: 1
[All PT0-002 Questions]

A compliance-based penetration test is primarily concerned with:

  • A. obtaining PII from the protected network.
  • B. bypassing protection on edge devices.
  • C. determining the efficacy of a specific set of security standards.
  • D. obtaining specific information from the protected network.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RRabbit_111
Highly Voted 1 year, 3 months ago
Selected Answer: C
C. determining the efficacy of a specific set of security standards. A compliance-based penetration test is primarily concerned with determining whether a specific set of security standards are being met by the organization. The main goal is to assess the organization's compliance with these standards and identify any vulnerabilities or weaknesses that could potentially put sensitive data at risk. This could include testing for compliance with regulations such as HIPAA, PCI-DSS, SOX, etc. It does not focus on obtaining personal identifiable information (PII) or specific information from the protected network, or bypassing protection on edge devices.
upvoted 9 times
...
solutionz
Most Recent 9 months ago
Selected Answer: A
A. obtaining PII from the protected network. A compliance-based penetration test focuses on assessing an organization's adherence to specific security standards and regulatory requirements. The primary concern of this type of test is to identify vulnerabilities and weaknesses in the organization's security controls and processes, especially those related to compliance with relevant regulations and standards. Option A, obtaining PII (Personally Identifiable Information), aligns with the goal of a compliance-based penetration test. The test aims to determine whether the organization adequately protects sensitive data, such as PII, in compliance with applicable data protection laws and regulations. While options B, C, and D might be relevant in some types of penetration tests, they are not the primary focus of a compliance-based test. The main objective is to assess compliance with specific security standards and regulatory requirements, rather than actively bypassing edge devices or obtaining specific information from the protected network.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago