Answers |Guaranteed to Pass
Which phase of the NSA-IAM standard includes tasks such as conducting an opening meeting
and developing initial recommendations? ✔Correct Answer-On-site assessment
The actual penetration test, the attack phase of the NIST 800-115 standard, is a cyclical process
that is divided into how many steps? ✔Correct Answer-4
Which of the following techniques in the execution phase of the NIST 800-115 standard
identifies communication paths and facilitates the determination of network architectures?
✔Correct Answer-Network Discovery
Which of the following is not one of the three conceptual areas of PCI DSS testing concepts that
must be addressed prior to the test engagement? ✔Correct Answer-Planning
In which stage of the PTES penetrating testing process will you actually attempt to breach the
target network? ✔Correct Answer-Exploitation
The Pen Testing Execution Standard (PTES) recommends how many stages? ✔Correct Answer-
7
In which stage of the penetration testing process does the PTES recommend first defining the
scope? ✔Correct Answer-Pre-engagement interactions
Which of the following is well known for their list of the top vulnerabilities found in web
applications in the previous year? ✔Correct Answer-OWASP
Which security standard recommends best practices for initiating, implementing, and
maintaining information security management system (ISMS)? ✔Correct Answer-ISO-27002
Which of the following statements about CREST is true? ✔Correct Answer-CREST is not a
standard; it is a certification.
Which of the following penetration testing standards uses these three phases: Planning,
Execution, and Post-Execution? ✔Correct Answer-NIST 800-115
Which of the following is the penetration testing standard used by Visa, Mastercard, American
Express, and Discover? ✔Correct Answer-PCI DSS
Which of the following is a not for profit organization that originated in the UK and offers
training and certification in cyber security? ✔Correct Answer-CREST