Which two statements are true about penetration tests and vulnerability assessments? (Choose two.)
- A penetration test is an intrusive test that attempts to exploit vulnerabilities.
- A vulnerability assessment is a nonintrusive test that attempts to exploit vulnerabilities.
- A penetration test is a passive test that attempts to discover vulnerabilities.
- A vulnerability assessment is a passive test that attempts to discover vulnerabilities.
- No permission is required before conducting a vulnerability assessment and penetration test.
Explanation & Hint:
The two statements that are true about penetration tests and vulnerability assessments are:
The statement “No permission is required before conducting a vulnerability assessment and penetration test” is not true. Permission and proper authorization are crucial before conducting both vulnerability assessments and penetration tests to ensure the organization is aware of and consents to the testing, and to avoid any potential legal or operational issues. Unauthorized testing can lead to disruptions and legal consequences. |