exam questions

Exam 312-50 All Questions

View all questions & answers for the 312-50 exam

Exam 312-50 topic 5 question 40 discussion

Actual exam question from ECCouncil's 312-50
Question #: 40
Topic #: 5
[All 312-50 Questions]

When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual
(OSSTMM) the main difference is

  • A. OWASP is for web applications and OSSTMM does not include web applications.
  • B. OSSTMM is gray box testing and OWASP is black box testing.
  • C. OWASP addresses controls and OSSTMM does not.
  • D. OSSTMM addresses controls and OWASP does not.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
melante
3 years, 8 months ago
what about A since OSSTMM is for network security? EC-Council states that "The updated guide of OWASP provides over 66 controls to identify and assess vulnerabilities with numerous functionalities found in the latest applications today." (reference: https://blog.eccouncil.org/5-penetration-testing-methodologies-and-standards-for-better-roi/) so OWASP does include controls!
upvoted 1 times
Script_Kitty
11 months, 1 week ago
Agreed, I believe A is the right answer.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...