Question: A penetration - testing firm is working with a local community bank to create a proposal that best fits the needs of the bank. The
A penetrationtesting firm is working with a local community bank to create a proposal that best fits the needs of the bank. The bank's information security
manager would like the penetration test to resemble a real attack scenario, but it cannot afford the hours required by the penetrationtesting firm. Which of the
following would best address the bank's desired scenario and budget?
A Engage the penetrationtesting firm's redteam services to fully mimic possible attackers.
B Give the penetration tester data diagrams of core banking applications in a knownenvironment test.
C Limit the scope of the penetration test to only the system that is used for teller workstations.
D Provide limited networking details in a partially knownenvironment test to reduce reconnaissance efforts.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
