exam questions

Exam 312-50v8 All Questions

View all questions & answers for the 312-50v8 exam

Exam 312-50v8 topic 8 question 17 discussion

Actual exam question from ECCouncil's 312-50v8
Question #: 17
Topic #: 8
[All 312-50v8 Questions]

What is the benefit of performing an unannounced Penetration Testing?

  • A. The tester will have an actual security posture visibility of the target network.
  • B. Network security would be in a "best state" posture.
  • C. It is best to catch critical infrastructure unpatched.
  • D. The tester could not provide an honest analysis.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Real life attacks will always come without expectation and they will often arrive in ways that are highly creative and very hard to plan for at all. This is, after all, exactly how hackers continue to succeed against network security systems, despite the billions invested in the data protection industry.
A possible solution to this danger is to conduct intermittent "unannounced" penentration tests whose scheduling and occurrence is only known to the hired attackers and upper management staff instead of every security employee, as would be the case with "announced" penetration tests that everyone has planned for in advance. The former may be better at detecting realistic weaknesses.
References: http://www.sitepronews.com/2013/03/20/the-pros-and-cons-of-penetration-testing/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Currently there are no comments in this discussion, be the first to comment!
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...