CAP: Security Assessment and Authorization Certification - Types of Penetration Tests

Types of Penetration Tests

Question

Which of the following is NOT a type of penetration test?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

Penetration testing is a type of security testing that involves evaluating the security of an information system or network by simulating an attack by a malicious actor. It is used to identify vulnerabilities and potential attack vectors that can be exploited by hackers to gain unauthorized access to sensitive information.

There are different types of penetration tests, and each type is designed to simulate a specific type of attack scenario. The goal of each test is to identify vulnerabilities in the system and provide recommendations for remediation.

The answer to the question is A. Cursory test. A cursory test is not a type of penetration test. A cursory test is a quick and informal test that is used to identify obvious vulnerabilities in a system. It is not a comprehensive test and does not involve in-depth analysis or simulation of attacks.

The other types of penetration tests are:

B. Partial-knowledge test: In this type of test, the tester has some knowledge about the system or network being tested, such as network architecture, application details, or credentials. This test simulates an attack by an insider or a hacker who has limited knowledge about the system.

C. Zero-knowledge test: In this type of test, the tester has no knowledge about the system or network being tested. This test simulates an attack by a hacker who has no prior knowledge of the system.

D. Full knowledge test: In this type of test, the tester has complete knowledge about the system or network being tested. This test is used to evaluate the effectiveness of security controls and to identify vulnerabilities that may be missed in other types of tests.

In summary, a cursory test is not a type of penetration test. The other types of penetration tests are partial-knowledge test, zero-knowledge test, and full-knowledge test.