Which THREE of the following are common methods used in security assessment and testing? (Select exactly 3.)
Penetration testing is a highly effective and common method for proactively assessing an organization's security posture by simulating real-world attacks. Ethical hackers attempt to exploit identified vulnerabilities in systems, applications, and networks to determine the extent to which an attacker could compromise assets. This hands-on approach provides valuable insights into the effectiveness of existing security controls and the potential impact of a successful breach.
Why this answer
Penetration testing is a common method in security assessment and testing that simulates real-world attacks to identify exploitable vulnerabilities. Unlike vulnerability scanning, which only identifies potential weaknesses, penetration testing actively exploits them to validate security controls and measure the impact of a breach.
Exam trap
The trap here is that candidates confuse risk analysis (a management activity) with security testing, or mistake forensic analysis (a reactive process) for a proactive assessment method, leading them to select options outside the three correct ones (penetration testing, security auditing, vulnerability scanning).